Exoskeleton for your Mac.

Try MacCrab.

Interactive preview · fictional activity

High Fictional example

An agent accessed a credential file.

Claude Code zsh node

~/.aws/credentials

Access was observed. Theft is not established.

Interactive preview

Explore MacCrab

  • Alerts. Severity counts and a triage table. Each alert opens an inspector with what happened, the rule and what to do.
  • Investigation. TraceGraph links a suspicious event to the process behind it, and to the AI agent when one is involved. Agent Traces lists the spans an AI agent reported; their trace ID is what ties them to kernel events.
  • Forensics. 26 built-in scanners, the signed plugin catalog and two plugins installed from it. Each run collects evidence you can review and export.
  • Detection. Browse the current rule library with MITRE techniques and source YAML.
  • Your Mac. Explore Overview, Events, Prevention, Intelligence, System and Docs.

Interactive preview of the current v1.22.6 development build, with fictional activity. App source. Changes reset on reload; Agent Traces is shown enabled. The download above is the published v1.22.5 release.

See what’s happening, as it happens.

MacCrab reads Apple’s Endpoint Security feed, the same kernel-level events macOS gives to security tools, and turns it into readable alerts on your Mac.

  • AI coding tool monitoring

    Claude Code, Codex, Cursor and Copilot are powerful, and sometimes they wander. MacCrab alerts on credential reads, writes outside the project, prompt injection in commands and new MCP servers. It doesn’t block.

  • Agent Traces

    Line up what an AI agent did on your Mac with the agent’s own OpenTelemetry trace of its model and tool calls. Off until you turn it on.

  • Supply-chain worms

    Flags Shai-Hulud-style worms when a package install reads a developer credential, then contacts a registry or GitHub’s API. Plus typosquat scoring and opt-in decoy files.

  • Persistence and malware

    LaunchAgents and Daemons, dylib injection, quarantine-stripped payloads, kernel-cache rebuilds and TCC tampering, flagged by rules with a Sigma-compatible core.

  • Credential theft

    Keychain dumps, Chrome and Safari password-store reads, Wi-Fi password extraction, and SSH or AWS key reads by AI tools and package installs. Honeyfiles are opt-in.

  • Attack campaigns

    MacCrab correlates related alerts by process, ATT&CK tactic and time window. Different detectors use different thresholds to surface patterns across a multi-step intrusion.

AlertsSimulated
  1. —execclaude/Users/crabby/.local/share/claude/versions/2.1.284
  2. —execnodeparent claude
  3. —opennode/Users/crabby/.ssh/id_ed25519
mediumT1552.001

🦀 AI Tool Accessed SSH Private Key

maccrab.ai-guard.credential-access

What happened

node (via claude) open /Users/crabby/.ssh/id_ed25519

Read the source: CredentialFence.swift

A simulation with example paths. Each detection links to its current app source.

Rules shipped
486
Built-in detections
46
Built-in scanners
26

Library counts from the v1.22.5 build record, not a measure of validated detection coverage. Only the stable tier (116 rules in v1.22.5) is on by default; experimental rules are opt-in. Read the rules or the release record.

Forensics, on demand. Choose from 26 built-in scanners or add a plugin from the signed Rave catalog. Review what it collects, run a scan, then inspect and export the evidence. Try an example scan.

Native app screenshots

Native app screenshots v1.17.6 archive · 5 workspaces

These captures show an earlier interface. For the current development build, explore the interactive preview above.

MacCrab's Overview workspace: a green 'Protected — system is secure' banner, KPI tiles for security grade, open alerts and campaigns, and a seven-day alert-volume chart.
Overview in v1.17.6. The old protection banner and dashboard. Current builds distinguish engine health from findings that need review.
Alerts workspace: severity counters over a triage table listing correlated alerts such as Cross-Process Attack Chain and Direct Keychain Database File Access, with bulk suppress and export actions.
Alerts. Triage by severity, suppress in bulk and export.
Events workspace: a live table of Endpoint Security events with time, action, category, process, detail and signer columns, and a detail pane for a selected file-deleted event.
Events. The live Endpoint Security stream, with the signer and lineage of every event.
Intelligence workspace, Threat Intel tab: a panel for adding custom feeds and indicators, and the abuse.ch feed settings.
Intelligence. Add your own hashes, IPs and domains. The abuse.ch feeds are opt-in; URLhaus and MalwareBazaar need an Auth-Key.
System workspace, Health tab: daemon uptime, collector health, event rate and lifetime totals, with a list of active collectors.
System. Daemon uptime, event rate and the health of every collector.

Historical screenshots from v1.17.6. Status labels and controls have changed since this release.

Prefer the terminal?

Inspect alerts, traces and scans with maccrabctl. Included with the Homebrew install.

Try the CLI preview
maccrabctlSimulated
crabby@maccrab-mbp ~ % maccrabctl alerts
7 alert(s) — last 7
══════════════════════════════════════════════════════════════
[HIGH]     06OCT2026 2:14:12 PM Agent Read Credential Material (Traceparent-Bound)
   Process: node (/opt/homebrew/Cellar/node/24.9.0/bin/node)
   MITRE: attack.t1555,attack.t1552.001,attack.t1552.004

[MEDIUM]   06OCT2026 2:14:12 PM 🦀 AI Tool Accessed AWS Credential
   Process: node (/opt/homebrew/Cellar/node/24.9.0/bin/node)
   MITRE: attack.t1552.001

[CRITICAL] 06OCT2026 2:09:12 PM Gatekeeper Disabled via spctl
   Process: spctl (/usr/sbin/spctl)
   MITRE: attack.t1553.001

[HIGH]     06OCT2026 1:47:12 PM Unsigned binary from a download path created persistence
   Process: updater (/Users/crabby/Library/Application Support/.updater/updater)
   MITRE: T1543.001,T1547

[HIGH]     06OCT2026 1:47:12 PM LaunchAgent Created by Unsigned Process
   Process: updater (/Users/crabby/Library/Application Support/.updater/updater)
   MITRE: attack.t1543.001

[MEDIUM]   06OCT2026 11:07:12 AM Socat TCP Relay or Command Execution
   Process: socat (/opt/homebrew/Cellar/socat/1.8.0.3/bin/socat)
   MITRE: attack.t1095

[LOW]      05OCT2026 11:05:12 PM Shell Spawned by Browser Process [SUPPRESSED]
   Process: fish (/opt/homebrew/bin/fish)
   MITRE: attack.t1059.004

crabby@maccrab-mbp ~ % 

A simulation with example data. Selected commands from the v1.22.6 development build; example output shares this page’s app state.

Your data. Your device.

Detection data is a full picture of what happens on your machine, so it should stay there. MacCrab keeps events in a local SQLite database, runs analysis on-device by default, and ships no telemetry unless you turn it on.

  • On-device by default. Fleet telemetry, threat-intel feeds and cloud AI backends are opt-in.

  • No account. No signup and no license server.

  • Local AI first. Ollama is the recommended backend. A cloud backend gets a best-effort redaction pass before anything leaves your Mac.

  • Open source. Code under Apache 2.0 and detection rules under DRL 1.1, all on GitHub.

Give your Mac an exoskeleton.

Free, signed and notarized for macOS 13+. A public alpha for developers and security practitioners; expect false positives.

Published release

v1.22.5: artifact checks passed.

The download’s checksum, signatures, notarization and source attestation were checked against the actual DMG. Runtime qualification remains incomplete.

Read the checks & gaps

Homebrew Recommended

Installs the signed, notarized app and command-line tools in one command.

brew install --cask peterhanily/maccrab/maccrab

Direct download

Drag MacCrab to Applications. The built-in updater uses the Sparkle feed.

Download MacCrab v1.22.5

From source

Swift 5.9 or later. make dev builds every target with ad-hoc signing, for development.

git clone https://github.com/peterhanily/maccrab
cd maccrab && make dev

On first launch, approve the system extension and grant Full Disk Access. When removing MacCrab, deactivate the extension before deleting the app. Removal steps.

Common questions.

The long answers live in the README.

What is MacCrab?

MacCrab is a local-first macOS threat detection engine. It uses Apple's Endpoint Security framework, detection rules (Sigma-compatible core), behavioral scoring, campaign correlation, and opt-in Agent Traces (W3C TRACEPARENT correlation between AI-agent activity and kernel events) to surface suspicious activity on your Mac — on-device by default, with no cloud console or account.

Does MacCrab replace my antivirus?

No. MacCrab complements macOS's built-in defences (Gatekeeper and XProtect) and existing antivirus products. It focuses on behavioural detection and Sigma-rule threat hunting rather than signature-based scanning, so the two are additive.

Is any of my data sent to a cloud service?

Detection events and analysis stay on your Mac by default. The app does make a daily software-update request to maccrab.com, which reveals your source IP, app and Sparkle versions, and ordinary request metadata—not detection data. Opening the Rave catalog or installing plugins also makes network requests. Fleet telemetry, threat-intelligence feeds and cloud AI backends are opt-in. Cloud AI requests use best-effort redaction; review the privacy documentation before enabling them. See every outbound connection and what it sends.

Which macOS versions does MacCrab support?

macOS 13.0 Ventura or later. On first launch you approve the System Extension: on macOS 15 or later in System Settings → General → Login Items & Extensions → Endpoint Security Extensions, and on macOS 13 and 14 by clicking Allow in System Settings → Privacy & Security. Then grant Full Disk Access for complete event coverage.

How does MacCrab compare to Santa or osquery?

They solve different problems. Santa is a binary allow/deny authorisation policy engine. osquery is a scheduled SQL query engine with a large ecosystem. MacCrab is real-time, Sigma-rule-based threat detection with behavioural scoring and campaign correlation. All three can run alongside each other.

Is MacCrab open source?

Yes. MacCrabCore's code is Apache 2.0; the detection ruleset is licensed under the Detection Rule License (DRL) 1.1. Both are hosted at github.com/peterhanily/maccrab — every collector, rule, sanitiser, and the daemon entry-point is readable.

How do I report a security vulnerability?

Email maccrab@peterhanily.com rather than opening a public GitHub issue. MacCrab follows responsible-disclosure practices documented in SECURITY.md.