Skip to content

Emond Clients

Evidence: Emond Clients
Description: Collect Emond Clients
Category: System
Platform: macos
Short Name: emnd
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Emond (event monitor daemon) can execute client scripts based on rules. This data is essential for detecting persistence via emond client files.

This collector gathers structured data about emond clients.

FieldDescriptionExample
FileNameFile NameExample value
FullPathFull PathExample value
HashHashExample value
FileSizeFile Size123
ModifiedModified2023-10-15 14:30:25+03:00
AccessedAccessed2023-10-15 14:30:25+03:00
ChangedChanged2023-10-15 14:30:25+03:00

This collector enumerates /private/var/db/emondClients/ and records file metadata and hashes into emond_clients.

This evidence is crucial for forensic investigations as emond clients have been used by malware for persistence.