#security-framework #macos #events #endpoint #wrapper #monitoring

endpoint-sec

High-level Rust wrappers around the Endpoint Security Framework

7 unstable releases (3 breaking)

0.4.1 Sep 19, 2024
0.4.0 Jun 21, 2024
0.3.4 Jan 22, 2024
0.3.2 Nov 30, 2023
0.2.0 Jul 12, 2023

#134 in Development tools

Download history 461/week @ 2024-07-20 652/week @ 2024-07-27 757/week @ 2024-08-03 311/week @ 2024-08-10 310/week @ 2024-08-17 445/week @ 2024-08-24 531/week @ 2024-08-31 346/week @ 2024-09-07 549/week @ 2024-09-14 518/week @ 2024-09-21 505/week @ 2024-09-28 1081/week @ 2024-10-05 736/week @ 2024-10-12 1036/week @ 2024-10-19 879/week @ 2024-10-26 869/week @ 2024-11-02

3,718 downloads per month

MIT/Apache

345KB
5.5K SLoC

Endpoint Security - Rust bindings

Endpoint Security (abbreviated ES here) is a framework provided by Apple for macOS machines for monitoring system events for potentially malicious activity, see the official documentation for the exact details.

This repository is composed of two Rust crates:

endpoint-sec-sys is the raw events translated from C to Rust, with some additional types that have to exist in the crate because of the orphan rules. While you can use the crate directly, no effort have been made to make it easy nor correct.

endpoint-sec contains the higher level wrappers. They're much safer and more ergonomic to use but incur a slight overhead cost in certain methods (not all, not even most of them).

MSRV

Current MSRV is 1.70.0. It can be updated in any minor version, though we'll try to be conservative with it.

Contributing

All contributions are welcome, provided they respect the Rust Code of Conduct. Opening an issue to signal a bug is a contribution!

License

Dual licensed under Apache 2 and MIT, see the LICENSE-APACHE and LICENSE-MIT files.

Dependencies

~185KB