eslogger
executablemacOS1.1 MBx86_64, arm64
Endpoint security monitoring daemon — observes process, file, and network activity
Monitors system activity across processes, files, and network connections using the Endpoint Security framework. Collects telemetry on application behavior and system events, transmitting observations to Apple endpoints for analysis. Enforces security policies and rules by inspecting execution flows and file operations. Runs as a privileged system daemon with access to sensitive process and network state.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.1 MB
- UUID
- 9F816C3E-E103-3CB9-AEF9-9A503F8A10DF
- Analyzed
- 2026-04-07T05:21:14Z
- CDHash
- 4a2b853c132091e682761743af06674f2b34ab5019cde1abd15ed043effd7691
Capabilities
SecurityEndpoint Security (process/file/network monitoring)
/usr/lib/libEndpointSecurity.dylibFrameworks16
ArgumentParserInternallibEndpointSecurity.dylibFoundationlibobjc.A.dyliblibSystem.B.dylibTCClibswiftCore.dyliblibswiftCoreFoundation.dylib(weak)libswiftDispatch.dyliblibswiftIOKit.dylib(weak)libswiftObjectiveC.dylib(weak)libswiftSystem.dyliblibswiftXPC.dylib(weak)libswift_Builtin_float.dylib(weak)libswift_DarwinFoundation1.dyliblibswiftos.dylib
Entitlements3
Interesting Strings
Bundle IDs(9)
File Paths(3)
Network Surface
Networking Frameworks
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
0
Hardware
0
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
0
File Paths
3
Bundle IDs
9
IOKit Constants
0
Library Functions
4
Structural HashesSHA-256
Static Libraries4 / 2796 functions identified
Identified Libraries
Functions(2796)
0x100001130sub_100001130
0x100001250sub_100001250
0x100001294sub_100001294
0x1000012e8sub_1000012e8
0x1000012f4sub_1000012f4
0x100001348sub_100001348
0x100001390sub_100001390
0x1000013f4sub_1000013f4
0x10000143csub_10000143c
0x10000146csub_10000146c
0x100001484sub_100001484
0x1000014a0sub_1000014a0
0x1000014b4sub_1000014b4
0x1000014fcsub_1000014fc
0x100001548sub_100001548
0x100001558sub_100001558
0x100001578sub_100001578
0x100001bd0sub_100001bd0
0x100001f24sub_100001f24
0x100001f68sub_100001f68
Imports435 symbols from 11 dylibs
Exports1
_mh_execute_header0x0