Glossary
Endpoint Security Framework
Endpoint Security is the macOS API that lets approved security tools monitor and authorize process, file and system events in user space.
The Endpoint Security framework is an Apple API, introduced in macOS Catalina, that lets security products observe and control system activity without a kernel extension. A client subscribes to event types such as process execution, file opens, file renames, mounts and signal delivery. It receives detailed information about each event, including the process involved and its code-signing identity.
There are two kinds of events. Notify events report that something happened, which suits logging and detection. Authorization events pause the operation until the client allows or denies it within a deadline, which enables tools such as binary authorization systems to block unapproved executables.
Endpoint Security clients require a special entitlement granted by Apple, typically run as system extensions, and need Full Disk Access, which organizations usually pre-approve with a PPPC profile. Most modern EDR products for macOS are built on this framework. Apple also includes eslogger on macOS Ventura and later, which prints Endpoint Security events for investigation and testing.
See the unified logging and Endpoint Security guide for detection practices.