Crescendo icon
Crescendo icon

Crescendo

Crescendo is a real time event viewer for macOS that uses the ESF to show process executions and forks, file events, share mounting events, kernel extension loads, and IPC event data. ESF provides a vast amount of data, but the goal was to just pick out the things that analysts...

Crescendo screenshot 1

Cost / License

  • Free
  • Open Source

Platforms

  • Mac
-
No reviews
0likes
0comments
0news articles

Features

Suggest and vote on features
No features, maybe you want to suggest one?

 Tags

  • event-log
  • event-viewer

Crescendo News & Activities

Highlights All activities

Recent activities

No activities found.

Crescendo information

  • Developed by

    Stephen Davis
  • Licensing

    Open Source and Free product.
  • Alternatives

    23 alternatives listed
  • Supported Languages

    • English
Crescendo was added to AlternativeTo by Paul on and this page was last updated .
No comments or reviews, maybe you want to be first?
Post comment/review

What is Crescendo?

Crescendo is a real time event viewer for macOS that uses the ESF to show process executions and forks, file events, share mounting events, kernel extension loads, and IPC event data. ESF provides a vast amount of data, but the goal was to just pick out the things that analysts would be interested in when analyzing a piece of malware or trying to understand how a process (or component) works. Just the right amount of data without being a firehose of events to the user. Features

  • System Extension using Endpoint Security Framework
  • Real time event viewer and event detail viewer
  • Search for easy filtering of events by process, PID, username, or event type
  • Filters for unsigned apps vs apple signed apps
  • Ability to export all events to JSON
  • Context highlighting when unsigned apps are executed

Apple has added some extra security features that require some extra setup for enabling Crescendo’s system extension. Head on over to the Getting Started section in the README to get started. I’m hopeful this inconvenience will be fixed in future versions.