MONITOR CAPTURES TRACEABLE IDs
PAIRVERIFY CRYPTOGRAPHIC HANDSHAKE CAPTURED
SELF-AUTHENTICATING UNDER FRE 902
APPLE RAPPORTD OUTPUT — UNALTERED
MONITOR CAPTURES TRACEABLE IDs
SHA-256 CHAIN OF CUSTODY — TAMPER-EVIDENT LOG SEALING
MONITOR CAPTURES TRACEABLE IDs
PAIRVERIFY CRYPTOGRAPHIC HANDSHAKE CAPTURED
SELF-AUTHENTICATING UNDER FRE 902
APPLE RAPPORTD OUTPUT — UNALTERED
MONITOR CAPTURES TRACEABLE IDs
// How It Works
Plug it in. It captures the invisible — unknown devices, crowdsourced operations, individuals — authenticating against your Apple account through unauthorized MDM/DDM installation without your knowledge, their proximity to you, use of their peer-to-peer connection to your device to obtain screen sharing, camera sharing and keyboard access.
The evidence is immutable. Every captured device is logged, timestamped, and sealed under a SHA-256 chain of custody that cannot be altered without breaking the math.
Print the Vault Hardening Report. Hand it to your attorney.
The logs are presumed authentic under Federal Rules of Evidence 902(13) and 902(14). The defendants have to prove the impossible — that the math is wrong.
This type of exploit is undetectable to the user and to the Apple Store Genius Bar. Apple will tell you to wipe your hard drive which has no effect. If you hand our FM report to the Apple Store you will find they have no protocol in place for the criminal use of their MDM software and send you away without a repair and do not report it to the corporate office. Compounding this, once the nefarious DDM is installed there is no cap on the amount of unauthorized accounts that can be added.
ZERO TRUST EXECUTIVE PERIMETER
Forensic Account Monitor is purpose-built for executives and high-value targets who require an independent security perimeter — including scenarios where the threat originates from inside their own IT infrastructure.
Unlike enterprise MDM solutions that route telemetry through managed servers, this tool reads Apple's native system daemons directly on the monitored device and writes output locally. There is no cloud dependency, no managed endpoint, and no third-party data handling. The monitoring chain cannot be intercepted, altered, or disabled by a network-level administrator.
WHO THIS TOOL IS FOR
Forensic Account Monitor is most useful for typical targets of crowdsourcing campaigns — individuals and professionals whose positions, work, or beliefs make them targets of coordinated swarming tactics.
Corporate Deployment
Once approved by your IT department, law partners, and accounting partners, corporate executives can use it as an independent audit layer that operates entirely outside the managed IT perimeter — providing a ground-truth record in the event your IT department is collecting unauthorized data or has provided unauthorized access to your device.
Government and Law Enforcement Personnel
ICE and Border Patrol agents, judges, politicians, and public health officials are frequent targets of organized harassment campaigns that use proximity-based surveillance to track movements and monitor communications.
Whistleblowers and Dissidents
Corporate whistleblowers and political dissidents face well-resourced adversaries with the organizational capacity to deploy the kind of MDM-based fleet infrastructure this tool is specifically designed to detect.
Activists and Journalists
Those who investigate extremist groups, cults, or organized crime are routinely subjected to swarming tactics. This tool documents those operations in real time using Apple's own self-authenticating system logs — producing evidence that is admissible in federal court.
Celebrities and Public Figures
High-profile individuals — entertainers, athletes, executives, and social media personalities — are increasingly targeted by coordinated proximity-based surveillance operations. Their public schedules, recognizable locations, and high-value personal data make them prime targets for the kind of organized, technology-enabled stalking this tool is specifically designed to detect and document.
01
Apple's Own Software Writes the Evidence
The script reads rapportd — Apple's Continuity authentication daemon — in real time using macOS's built-in log stream command. Every entry in the output is written by Apple's software, not by this tool. The monitor captures; it does not generate.
02
PairVerify Proves Prior Enrollment
For a device to authenticate as owner of your Apple account via DirectLink, it must pass Apple's PairVerify M2 challenge-response cryptographic handshake. This requires a private key generated at enrollment and registered on Apple's Identity Services servers. Proximity alone cannot produce this result. Every captured device is pre-enrolled before any proximity event occurred.
03
Four Parallel Streams, Zero Latency
The monitor runs four concurrent streams: RSSI proximity trapping via rapportd, SameAccountDevice authentication monitoring, MAC address harvesting with repeat-offender tracking, and BLE early warning via bluetoothd. All four run simultaneously in the background and write to separate log files.
04
Real-Time Push Alerts, Tiered by Severity
Every event triggers a push notification to your iPhone or Android device via Pushover, prioritized by severity — from normal proximity approach to emergency-level owner access and batch credential deployment events. New MAC addresses and repeat offenders are distinguished automatically.
05
Self-Authenticating Under FRE 902
Log output qualifies as self-authenticating under Federal Rule of Evidence 902 as records generated in the ordinary course of system operation. The LIVE_STREAM.log produced by this tool constitutes the primary forensic record produced by this tool.
// Installation
🖥
macOS Ventura 13 or later
Tested on macOS Sequoia 15 / MacBook Air M4
📲
Pushover Account
Free 30-day trial · $5 one-time per platform · pushover.net
🔐
Terminal Full Disk Access
System Settings → Privacy & Security → Full Disk Access
📦
No Additional Dependencies
bash and curl are pre-installed on every Mac
INTEGRATED COMPONENTS
SHA-256 Vault Daemon
The SHA-256 Vault Daemon provides a complete, unbreakable evidentiary chain. The optional LaunchDaemon installer unlocks several capabilities unavailable to a standard terminal script: root-level execution, tamper-proof hash sealing in a user-inaccessible vault, automatic restart on crash, and persistence across logout and reboot — running continuously whether or not anyone is logged in.
Legal-Ready Audits
The vault installer generates a timestamped Hardening Report automatically on installation — and on demand at any time via generate_report.sh. Each report documents daemon status, vault integrity, live forensic statistics, and asserts the evidentiary basis under Federal Rules of Evidence 902(13) and 902(14). The report is sealed in the root vault and its SHA-256 hash is appended to the master chain of custody at the exact moment of generation. Run it before any court filing, discovery response, or supplemental submission.