Repository navigation
Download
GhostProcessSniper-2.1.0.dmg · universal (Apple silicon and Intel) · macOS 26 Tahoe or later
- Open the disk image and drag Ghost Process Sniper into Applications.
- Open it from Applications. It lives in the menu bar; choose Open Dashboard for the full console.
- The app is signed but not notarized, so the first launch shows "Apple could not verify…". Click Done, then open System Settings › Privacy & Security and click Open Anyway. macOS remembers the choice.
Updating from an earlier version: quit Ghost from its menu, replace the app in Applications, and open it again. Settings and history are kept.
What's new
Sentinel, a security watch that explains what it sees; a console that does about half the layout work; numbers that read the same in every language; and releases built in the open, with provenance you can verify.
Sentinel security watch
- A new Security section (⌘3) looks at every process for the shapes attacks take on macOS and explains each finding with the chain that launched it (
Google Chrome › zsh › curl), the exact text that matched, and one next step. - Catches browsers, mail, chat and document apps starting shells or scripts; pasted commands that download and run code (with advice about fake CAPTCHA and "fix" instructions); base64 and other encoded payloads; homemade password dialogs and
dscl -authonly; keychain, browser-cookie and wallet theft; quarantine stripping and Gatekeeper disabling; launch-agent persistence; reverse shells and shells or relays waiting for connections; tunnels; crypto miners; silent screen and camera capture. - Flags programs running from temporary, shared or hidden folders, the Trash, mounted disk images or Downloads, deleted executables, system names from the wrong folder or spelled with look-alike letters, and apps disguised as documents (
Invoice.pdf.app). - Checks each third-party program's code signature once, offline (Apple, App Store, Developer ID, ad hoc, unsigned, invalid), and shows the page it was downloaded from.
- Watches browsers and terminals with kernel process events, so commands that run for under a second are caught with their arguments, at no cost while nothing starts.
- Lists launch agents and daemons and catches new ones the moment they are written, with a notification.
- Shows which apps are recording from the microphone and whether a camera is on, from system listeners that open no device and need no permission.
- A live launch feed of every new process, a banner above the Overview, a raised menu-bar icon and one notification per new suspicious or dangerous program and reason; a program that restarts for the same reason stays silent for a day. Findings never act on their own: Stop… uses the usual preview, and programs can be trusted or findings dismissed.
- Stays quiet on everyday work that resembles an attack: simulator daemons, browser-extension helpers, compiler output, port checks, cookie-jar files, downloads named after wallets, signed programs in
/Users/Sharedand dev servers built into/tmp. The attack shapes they resemble are still caught.
Power
- The console's detail column no longer measures the whole page for its minimum size on every update; that was about half of the console's main-thread time while it was on screen.
- An open console refreshes at half, then a quarter, of its usual rate when nobody has touched the Mac for 30 seconds or 2 minutes, and returns to the full rate on the next tick after any input.
- Incident recurrence counts are cached between flushes instead of being queried on every scan.
- The two-column layout measures each child once per layout pass.
- Measured with the console frontmost: about 42% of a core before, 23–28% after, including Sentinel (Performance).
Interface
- Sections are ⌘1 Overview, ⌘2 All Processes, ⌘3 Security, ⌘4 Duplicates, ⌘5 Incidents, ⌘6 Rules, following the sidebar order.
--section security(or any section name) opens the console on that page at launch.
Fixed
- Temperatures and PIDs are formatted the same way in every locale: a Danish Mac no longer shows
91,0°Cnext to91.0°C, orPID 12.273in the stop preview. - The Overview's recommendation says what a stop does once; it read "Asks ChatGPT to quit like ⌘Q, then stops anything it leaves behind. ChatGPT is asked to quit like ⌘Q…".
- Ghost no longer lists itself under Warming Up or in the Risk Queue while its console is open. It still appears in All Processes, and Settings › Diagnostics shows what it costs.
Distribution
- Releases are built from the tagged source by GitHub Actions. Each disk image carries a signed build-provenance attestation, so
gh attestation verify GhostProcessSniper-2.1.0.dmg --repo mikkel32/ghost-process-sniperproves the file came from that build. - A website, mikkel32.github.io/ghost-process-sniper, with the download, install steps and checksum. It loads nothing from other sites.
- Release notes are generated from this changelog and include the checksum and first-launch steps.
Verify the download
SHA-256: ce4f92f5ff09f9564f898d41688bc47a40ffb6d5d6c20f4e39cd9938a97d4bf5
shasum -a 256 -c GhostProcessSniper-2.1.0.dmg.sha256This disk image was built from the tagged source by the Release workflow, which publishes a signed build-provenance attestation. With the GitHub CLI you can confirm the file came from that build:
gh attestation verify GhostProcessSniper-2.1.0.dmg --repo mikkel32/ghost-process-sniperPrefer to build it yourself? git clone https://github.com/mikkel32/ghost-process-sniper && cd ghost-process-sniper && Scripts/dev.sh run (details).
Full changelog: v2.0.0…v2.1.0