Use Objective-See Tools
Overview
Select the Objective-See tool that observes the needed surface, record its current capabilities, and return evidence to the owning macOS workflow. Do not treat one tool's label or UI color as a threat verdict.
Read references/objective-see-routing.md and recheck the official tool page before use.
Workflow
- Name the unresolved observation: persistence, process, file, network, signing, or process inventory.
- Discover local capability.
- Verify official source, installed app/path, version, supported macOS build, permissions/system extensions, running state, and export format.
- Do not install, approve extensions, or grant privacy access without an explicit operator decision.
- Select one tool and bounded action.
- Preserve context.
- Record scan time, filters, exclusions, baseline, UI/CLI actions, alerts, raw/exported output, and tool errors.
- Correlate independently.
- Verify signer/path/hash, process ancestry, persistence registration, socket, or file change with native evidence where practical.
- Route conclusions.
- Send evidence to persistence, runtime, threat assessment, or containment workflows.
Guardrails
- Do not enable blocking rules or terminate/delete items during evidence collection unless containment is separately approved.
- Do not claim historical coverage when the tool was installed after the event.
- Do not assume every Objective-See tool exposes a stable CLI or accessible GUI automation surface.
Output
Return tool/version/capability, permissions, action, observations/export, independent correlation, limitations, and owning workflow.
1---2name: use-objective-see-tools3description: Use installed Objective-See macOS security tools as evidence adapters. Use for KnockKnock, BlockBlock, LuLu, ProcessMonitor, FileMonitor, WhatsYourSign, TaskExplorer, or related tools with explicit permissions, limits, and ownership.4---56# Use Objective-See Tools78## Overview910Select the Objective-See tool that observes the needed surface, record its current capabilities, and return evidence to the owning macOS workflow. Do not treat one tool's label or UI color as a threat verdict.1112Read [references/objective-see-routing.md](references/objective-see-routing.md) and recheck the official tool page before use.1314## Workflow15161. Name the unresolved observation: persistence, process, file, network, signing, or process inventory.172. Discover local capability.18 - Verify official source, installed app/path, version, supported macOS build, permissions/system extensions, running state, and export format.19 - Do not install, approve extensions, or grant privacy access without an explicit operator decision.203. Select one tool and bounded action.214. Preserve context.22 - Record scan time, filters, exclusions, baseline, UI/CLI actions, alerts, raw/exported output, and tool errors.235. Correlate independently.24 - Verify signer/path/hash, process ancestry, persistence registration, socket, or file change with native evidence where practical.256. Route conclusions.26 - Send evidence to persistence, runtime, threat assessment, or containment workflows.2728## Guardrails2930- Do not enable blocking rules or terminate/delete items during evidence collection unless containment is separately approved.31- Do not claim historical coverage when the tool was installed after the event.32- Do not assume every Objective-See tool exposes a stable CLI or accessible GUI automation surface.3334## Output3536Return tool/version/capability, permissions, action, observations/export, independent correlation, limitations, and owning workflow.