What cmdReporter Does
cmdReporter is a security monitoring tool for macOS. Using minimal resources, cmdReporter collects the data IT security teams need to hunt threats to macOS and streams the logs in real time to nearly any analysis server.
Our approach filters and normalizes all logs coming from macOS into a single format that is easy for any log analysis software to parse and search.
There is no cmdReporter server, we are designed to integrate and stream directly from the mac to with nearly any SIEM, log collection, or data lake tool that your organization already uses to store and analyze computer logs.
Where cmdReporter Sends Data
Why cmdReporter is Different
cmdReporter is designed to work with macOS rather than against it. We do this by:
- No custom kernel extension.
- Near-zero performance impact.
- Use Apple APIs to collect our security information.
- Designing for macOS first rather than adapting a windows-based solution.
- 100% preference coverage for configuration profiles.
- Day-zero support for macOS releases.