Skip to content

About

A lightweight macOS auditing tool to inspect background services and persistence, with risk indicators, safe quarantine, and HTML reports.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

TinyMacAudit

TinyMacAudit 0.0.1 is an interactive Bash utility for inspecting macOS persistence and background components. It attributes executable signatures, explains review indicators, and can quarantine selected current-user LaunchAgents with verified backups.

It is not a malware detector, an uninstaller, or a compliance assessment. Recognized vendors are not automatically safe. Unknown vendors are not automatically malicious.

Installation and usage

Download the source into a local directory, inspect it, and run with the macOS system Bash. No Homebrew, Python, jq, or downloaded executables are required.

chmod +x tinymacaudit.sh
./tinymacaudit.sh --help
./tinymacaudit.sh scan
mkdir -p reports
./tinymacaudit.sh scan --output reports
./tinymacaudit.sh review
./tinymacaudit.sh restore

Add --login-items to query System Events; macOS may ask for Automation permission. Run as the logged-in user without sudo. Scan mode never changes discovered components. Reports are generated only when requested and are placed in a new private subdirectory. Review reports represent the scan before cleanup.

Example (illustrative):

category: User LaunchAgent
name: org.example.agent
vendor: unknown
signature: unsigned
loaded: no or inaccessible
risk: REVIEW
reasons: Executable is unsigned. Vendor could not be attributed.
removable: yes
[k] Keep [d] Quarantine [i] Details [f] Finder [q] Quit:

Coverage

Category Inspection Cleanup
User LaunchAgents Plist, executable signature, launchctl state Verified backup + unload + quarantine
System LaunchAgents / LaunchDaemons Same metadata, including Apple system directories Inspection only
PrivilegedHelperTools File and signature metadata Inspection only
Login Items Optional System Events inventory Use System Settings / owning app
Background Items sfltool dumpbtm diagnostic inventory Use System Settings / owning app
System / Network Extensions Native registrations and plugin inventories Use owning app
Configuration Profiles Visible configuration and enrollment inventory Inspection only; no MDM changes
cron / periodic Current user's crontab and visible system scripts Inspection only
StartupItems / kernel extensions Legacy filesystem inventory and loaded kext diagnostics Inspection only
Chrome / Edge Extension manifests across local profiles Use browser
Firefox Extension registry and XPI discovery Use browser
Safari Registered app and web extensions Use Safari

Some inventories contain multiple components in one record with raw native output under details. Counts therefore describe records, not unique installed components. Empty or failed commands never establish absence. Other users' data, inaccessible directories, sandboxed browser variants, developer-mode extensions, and all possible persistence techniques are outside complete coverage. Browser presence does not establish enabled state. Background task diagnostic output is OS-dependent. Network plugins and system extensions can overlap.

Safety model

Only a regular, owned, single-link plist immediately inside the current user's Library/LaunchAgents directory can be quarantined. Apple signatures and reserved Apple labels/filenames block cleanup. Symlinks, traversal, nested paths, root execution, and arbitrary user-entered deletion paths are rejected. Executables referenced by a plist are never removed.

Removal requires REMOVE, plus I UNDERSTAND for unknown vendors or non-LOW findings. Backups are verified before unloading. Quarantine uses a move rather than permanent deletion. Backups under ~/TinyMacAuditBackup/ preserve the plist, original path, timestamp, mode/ownership metadata, SHA-256, load state, and transaction state. Failed steps retain evidence. Restore verifies the backup, refuses overwrite, and does not automatically load the job. Restored jobs may run at next login.

See safety and recovery before cleanup. This tool does not change SIP, Gatekeeper, FileVault, XProtect, TCC, or MDM enrollment.

Reports and interpretation

Terminal counts and self-contained HTML/JSON reports include date, macOS version, model, architecture, vendors, findings, and explanations. Missing metadata is unknown or empty, never assumed safe. SHA-256 refers to the discovered file (for launchd: the plist); bundle directories are not recursively hashed. loaded reports registration visibility, not a guarantee that a process is running. Architecture is native file output; scripts and bundles may not have a CPU architecture.

LOW means no selected indicators were found. REVIEW identifies missing evidence or conditions worth inspecting. SUSPICIOUS identifies failed signature verification or execution from temporary locations. No numeric health score is used. Apple attribution of a launch job describes its executable, not authentication of the plist or its arguments.

Reports and backups contain private paths and potentially sensitive command output. Keep them local; review/redact before sharing. Existing reports from earlier versions are not converted or deleted.

Compatibility and validation

Targets macOS 13 and later, Intel and Apple Silicon, using Bash 3.2 syntax. Commands and permissions vary by OS release. Fixture tests and syntax checks were run on macOS 26; this is not a claim of certification across every OS/hardware combination. A full live audit and live cleanup require manual validation on disposable Macs before organizational deployment.

/bin/bash tests/run.sh
/bin/bash -n tinymacaudit.sh
for f in lib/*.sh tests/*.sh; do /bin/bash -n "$f" || exit; done

Architecture and contributing

tinymacaudit.sh coordinates scanners in lib/. Each finding is a private directory of scalar fields, preventing configuration text from becoming shell code. vendor.sh attributes signatures, health.sh explains indicators, report.sh serializes data, and backup.sh/restore.sh enforce mutation boundaries. Native diagnostic failures remain visible in inventory details.

See CONTRIBUTING.md, AGENTS.md, and SECURITY.md. Licensed under the MIT License.

About

A lightweight macOS auditing tool to inspect background services and persistence, with risk indicators, safe quarantine, and HTML reports.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages