{"repo":"nowsecure/fsmon","free":true,"listed":false,"github":"https://github.com/nowsecure/fsmon","clone":"git clone https://github.com/nowsecure/fsmon.git","description":"Filesystem monitor tool for Linux/Android iOS/macOS","language":"C","stars":1024,"topics":["tracing","osx","linux","android","filesystem","nowsecure","dynamic-analysis"],"license":"MIT","category":"mobile-apps","readme_excerpt":"fsmon Low level filesystem monitor utility for Linux, Android, iOS and macOS. - Author : pancake @ nowsecure - License : MIT Designed for - System administrators and incident responders - Security researchers and forensic analysts - Developers debugging I/O-heavy applications - Reverse engineers interested in observing filesystem access behavior Installation On macOS you can now install it via brew with these commands: Alternatively just run make or pick the builds from the release page. Usage The tool retrieves file system events from a specific directory and shows them in colorful format or in JSON. It is possible to filter the events happening from a specific program name or process id (PID). 🔍 Key Features of fsmon fsmon is a low-level, cross-platform filesystem monitor designed for developers, forensic analysts, and reverse engineers. It works by hooking into the OS kernel's tracing facilities or file notification APIs. ✅ Supported Platforms - Android : via inotify , fanotify is not always supported - Linux : via inotify and fanotify - macOS : using kdebug , FSEvents , kqueue , and /dev/fsevents - iOS (limited support through FSEvent APIs) Core Capabilities - Real-Time File Monitoring Detects and reports file operations such as creation, deletion, modification, attribute changes, and renames in real-time. - Multi-Backend Support Automatically selects the best available monitoring backend or allows users to choose: - inotify , fanotify (Linux) - fsevapi , kdebug , devfse","default_branch":null,"files":null,"tree":[],"storefront":"/r/nowsecure","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nowsecure/fsmon/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}