Skip to content
CAI
Software that uses CAICheck a score

Brandon7CC/mac-monitor

42.5

Weak · 1 October 2026

25.1k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a macOS security monitoring application named ProjectSutro (also referred to as Mac Monitor) that utilizes the Apple Endpoint Security framework to capture and analyze system events. It consists of a background security extension that subscribes to process execution and file activity, an in-memory Core Data store for high-performance event buffering, and a SwiftUI-based user interface for visualizing, grouping, and filtering these events. The codebase also includes educational examples and community build configurations to facilitate local development without proprietary signing certificates.

Features

Add AtomicESClient example for Apple Endpoint Security

Added a new educational Swift example, AtomicESClient, that demonstrates how to create an Endpoint Security client, subscribe to process execution events, and handle the resulting data. The addition includes the source code, an entitlements property list for the required \com.apple.developer.endpoint-security.client\ entitlement, a BSD 3-Clause license, and a README with build and signing instructions.

AtomicESClient · high confidence

Add community build configuration for development without signing certificates

Contributors can now build and run the application locally without access to the official Swiftly Detecting signing certificates or provisioning profiles. This is achieved by disabling Xcode's code signing step and using a new ad-hoc signing script that applies the necessary entitlements (such as endpoint-security.client) to the built artifacts. The resulting build is intended for use in virtual machines with System Integrity Protection (SIP) disabled, enabling local development and testing of the security extension and app components.

ProjectSutro, ProjectSutro/Scripts · high confidence

Added Community build configuration for development without signing certificates

Developers can now build and run the app using a new 'Community' build configuration, which allows development without the project's official signing certificates. This change introduces a dedicated Xcode scheme (ProjectSutro (Community)) and project settings that bypass code-signing requirements, facilitating local development and testing for contributors who do not have access to the internal signing keys.

ProjectSutro/ProjectSutro.xcodeproj · high confidence

Initial release of the Mac Monitor Security Extension

This change introduces the Security Extension component for Mac Monitor, enabling the agent to communicate with the system-level sensor via XPC. The extension registers an Endpoint Security client to monitor system events and exposes protocols for managing event subscriptions, path muting, and update checks. It includes the necessary asset catalog, entitlements (Endpoint Security client access and application group), and code-signing requirements to securely connect with the Mac Monitor agent.

ProjectSutro/SecurityExtension · high confidence

New Core Data model and controller for system event storage

The framework now includes a new Core Data model (BatchedEvents) and a dedicated CoreDataController to manage system events in an in-memory store. This change introduces a ThrottleManager to dynamically adjust save intervals based on event flow rates, improving performance during high-volume periods. Additionally, a comprehensive set of new Core Data entity classes (such as ESProcess, ESFile, ESStat, and EmittedEvent) has been added to support the storage and encoding of detailed process, file, and event artifacts.

ProjectSutro/SutroESFramework · high confidence

New event visualization, context menu, and grouping views

This update introduces several new SwiftUI views for the ProjectSutro interface. It adds an event chart view that counts and displays a standardized list of system events (such as EXEC, MPROTECT, and OPENSSH\_LOGIN). It also provides context menus for both execution and non-execution events, allowing users to filter by path, event type, or user ID, and to mute specific paths. Additionally, it introduces event grouping tables that let users view events organized by process or session, and adds metadata enrichment views to display audit tokens, dangerous entitlements, and code signing status.

ProjectSutro/ProjectSutro · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 37 → 43 (+5.3)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 96 → 86 (-10.1)
  • Architecture 99 → 100 (+0.5)
  • Maturity 35 → 51 (+15.7)
  • Readiness 5 → 10 (+4.7)
  • Security 92 → 92 (+0.0)
  • Domain Modelling 89 → 89 (+0.0)

Resolved (4)

  • Documentation: no usage examples (README.md)
  • Dormant codebase
  • Most significant orphaned file (ProjectSutro/SecurityExtension/XPC/RCXPC.swift)
  • Most significant orphaned file (ProjectSutro/SutroESFramework/ES Translation/ESEventsEnumerated.swift)

New (105)

  • AuthJudgeProcsView.body (cognitive 18) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Security Authorization/judgement/SystemAuthorizationJudementMetadataView.swift)
  • CoreDataController.insertSystemEvents (cognitive 21) (ProjectSutro/SutroESFramework/Core Data Controller/CoreDataController.swift)
  • Duplicated block (10 lines × 2) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Open Directory/SystemOpenDirectoryAttrAddMetadataView.swift)
  • Duplicated block (10–11 lines × 41) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Code Signing/SystemCodeSigningInvalidatedMetadataView.swift)
  • Duplicated block (11 lines × 3) (ProjectSutro/ProjectSutro/Main App View/Filter View/FilterView.swift)
  • Duplicated block (11 lines × 6) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/File System/close/SystemFileCloseMetadataView.swift)
  • Duplicated block (11–12 lines × 2) (ProjectSutro/ProjectSutro/System Event Views/Event Tables/Process/ProcessSystemEventsViews.swift)
  • Duplicated block (11–12 lines × 2) (ProjectSutro/ProjectSutro/System Event Views/Event Tables/Process/ProcessSystemEventsViews.swift)
  • Duplicated block (11–14 lines × 43) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/File Metadata/deleteextattr/SystemDeleteExtattrMetadataView.swift)
  • Duplicated block (12 lines × 4) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Open Directory/SystemOpenDirectoryCreateGroupMetadataView.swift)
  • Duplicated block (12–13 lines × 2) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Interprocess/trace/SystemProcessTraceMetadataView.swift)
  • Duplicated block (12–13 lines × 3) (ProjectSutro/ProjectSutro/System Event Views/Event Tables/Process/ProcessSystemEventsViews.swift)
  • Duplicated block (12–13 lines × 5) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/File System/close/SystemFileCloseMetadataView.swift)
  • Duplicated block (12–14 lines × 39) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/File Metadata/deleteextattr/SystemDeleteExtattrMetadataView.swift)
  • Duplicated block (13 lines × 2) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Open Directory/SystemOpenDirectoryAttrAddMetadataView.swift)
  • Duplicated block (13 lines × 2) (ProjectSutro/ProjectSutro/Main App View/Filter View/FilterView.swift)
  • Duplicated block (13 lines × 2) (ProjectSutro/SutroESFramework/ESM/Utilities/Path Muting/MuteSet.swift)
  • Duplicated block (14 lines × 2) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Enrichment Views/SystemEnrichedEventView.swift)
  • Duplicated block (14 lines × 2) (ProjectSutro/ProjectSutro/Event Facts Views/Event Metadata Views/Security Authorization/judgement/SystemAuthorizationJudementMetadataView.swift)
  • Duplicated block (14 lines × 2) (ProjectSutro/ProjectSutro/System Event Views/Event Tables/Process/ProcessSystemEventsViews.swift)
  • …and 85 more

Changes since last survey

  • 2 commits — 2 feature/other, 0 fixes

By area

  • (repo) — 1 commit
  • ProjectSutro/ProjectSutro.xcodeproj — 1 commit

Notable commits

  • change: Add Community build configuration for development without our signing certs
  • change: Merge pull request #85 from Brandon7CC/feature/community-development

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Brandon7CC/mac-monitor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 535933c07a071eeff81c11dfa4125a5911979d15 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.