Apple Endpoint Security Log Analyzer
Investigate Endpoint Security Activity in Your Browser
Upload one or more Apple Endpoint Security captures from eslogger or Mac Monitor (.json/.ndjson) and analyze them entirely in your browser. Files are processed locally on your device and are never uploaded to a backend.
No files selected. Drag files here or click to browse.
Waiting for files.
Filters And Export
Filter all views at once, then export the filtered timeline and rendered tree.
No filters applied.
Event Mix
Most frequent event categories in the filtered data set.
Sigma Rules
Match process creation (exec/fork) and file create/rename (create/rename) events against SigmaHQ macOS rules.
Load from another GitHub repo or upload one or more YAML files.
No Sigma rules loaded.
Timeline Story
Chronological high-signal events to reconstruct process behavior.
Process Tree
Fork/exec lineage with file activity, arguments, code-signing metadata, and observed exits. Click a node for details.