This project provides a macOS-based keylogger that captures both keyboard and mouse events. The keylogger is implemented in Objective-C and uses Apple's Carbon and ApplicationServices frameworks to monitor user input. It includes a macOS-specific helper script written in AppleScript to prompt users to grant necessary permissions.
- Event Capture: Logs keyboard presses and mouse interactions (clicks, drags).
- Selective Monitoring: Can capture only mouse events (
-mouse), only keyboard events (-keyboard), or both. - Assistive Access Setup: Includes an AppleScript (
mac_change_security_settings.scpt) to guide users through granting necessary permissions in macOS System Preferences.
- macOS: Tested on macOS 10.12 or later.
- Permissions: Requires "Accessibility" permissions for capturing input.
- Using Xcode:
- Open the project in Xcode.
- Select Product > Build to compile.
- Using
clang:- Run:
clang -o sniffMK sniffMK.m -framework Cocoa -framework Carbon
- Run:
To start the keylogger, run the compiled executable as follows:
- Mouse-only Events:
sudo ./sniffMK -mouse
- Keyboard-only Events:
sudo ./sniffMK -keyboard
- Both Events (default):
sudo ./sniffMK
Note: On first run, macOS may prompt to grant Accessibility permissions. See the AppleScript section below to automate permission setup. Modified from Patrick Wardle's Objective C tutorial.
The included AppleScript (mac_change_security_settings.scpt) checks if Accessibility permissions are enabled for the keylogger. If permissions are not granted, it guides the user through System Settings to enable them.
To run the script:
- Open
mac_change_security_settings.scptin the Script Editor. - Execute the script to prompt permission setup.
This project is for educational or testing purposes. Ensure usage complies with applicable laws and policies.