13 of 35 places coveredFirst Hour is not on the mapCatalog 8
Where each plugin looks.
A plugin marked “also” looks at that kind of thing as well as its own.
| Set upconfigured | Arrivedwhen it showed up | Nowhow it looks now | Gonethat it was removed | Traceswhat it left behind | |
|---|---|---|---|---|---|
| The Mac itself | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | ||
| A file |
|
|
| Nothing covers this yet | |
| An app or extension | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | ||
| A project | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | ||
| A secret | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | |
| A coding agent | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | Nothing covers this yet | |
| A directory account | Nothing covers this yet | Nothing covers this yet |
| Nothing covers this yet | Nothing covers this yet |
How to read the map
A name marked “from what you supply” relies on something you give it, like a snapshot or an export.
First Hour reads reports, so it is not on the map.
Rave’s editorial reading of the signed entries.
Nothing covers these yet
- The Mac itself: arrived, gone, traces
- A file: traces
- An app or extension: arrived, gone, traces
- A project: arrived, gone, traces
- A secret: set up, arrived, gone, traces
- A coding agent: arrived, now, gone, traces
- A directory account: set up, arrived, gone, traces
If you want to build a plugin, start here
- A plugin that can see a removal directly. An uninstalled app, a deleted launch item, a file in the Trash, a process that ended. Today the only way to see that something is gone is to compare two snapshots you dated yourself.
- Anything about traces. A launch item that points at a program that no longer exists, a hook that names a server that was removed, a port held open by an app that was uninstalled.
- When things arrived. We can see when a download arrived. We cannot see when an app, an extension, a hook or a repo did.
- What actually ran. No plugin here collects execution events. Dependency Autopsy matches execution records you supply, but cannot verify them.
- Local user accounts. Nothing here reads account creation, logins, privilege changes or deletions.
- Network beyond open ports: connections, DNS, what left the Mac, which networks it joined.
A dash is a plugin we want. A filled place needs a reason beyond doing the same thing another way.