macOS User Activity Monitoring
Manage access. Audit activity. Respond to incidents. ALL-IN-ONE
Ekran System® works to make your infrastructure as transparent as possible, increasing the visibility of user actions performed across various contexts, applications and platforms.
Besides Windows, Citrix, Linux, and UNIX, our insider threat protection product now delivers Mac desktop monitoring.
macOS session audit
A robust insider threat program should include tools to track and audit employee activity at their digital workplace. With macOS desktops conquering the enterprise market, companies need efficient macOS monitoring software to complement their existing security audit toolset.
Ekran System captures any user action together with its context in a rich recording format: user screen video recording with a multi-layer metadata index.
You can replay any session in the YouTube-like Ekran System player, watching video along with a synchronized detailed log. macOS monitoring metadata includes:
- Computer name
- User name
- Active application name
- Active window title
- URL currently open in a user’s browser
- Host / remote host IP address details
These multi-layer details index each moment of the recorded sessions. It allows you to search in and across recorded sessions not only on macOS but also on other platforms at the same time and quickly jump to the key episodes for a context-aware situation investigation.
Get the most value with multi-platform support
Be more proactive with alerts
Ekran System video + metadata Mac system monitoring format enables such a useful incident response tool as alerts on events.
After you have described a potentially critical event using a combination of rules around metadata (or chosen a set of them from the in-built Ekran System recommended alert pack), you indicate what actions should be performed automatically when this event is triggered:
- Send a notification with a link to the corresponding session
- Show a warning message to the user who triggered the alert
- Block the user who triggered the alert
- Kill the process (application), where the alert was triggered.
The capability to automatically and manually block potential malicious actions is a useful incident response tool complementing Mac activity monitor functionality.
Stay informed with reports
When performing Mac user activity monitoring with Ekran System, you get not only session records and investigation tools, but also a number of summary reports, which help you to build an overview of the current situation.
Reports include URLs visited, applications started, time spent and other summaries.
Besides reporting, Ekran System provides a forensic session record export feature to support your legal actions with reliable evidence.
Let’s get the conversation started
Contact our team to learn how our insider risk management software can safeguard your organization’s data from any risks caused by human factors. Book a call with us at a time that suits you best, and let’s explore how we can help you achieve your security goals.