TaskExplorer

See everything that's running on your Mac. TaskExplorer shows every process, live, along with its code signing status, loaded dylibs, open files, and network connections. Version 3.0 is a ground-up rewrite, built on Apple's Endpoint Security framework, with a built-in AI assistant.

Download v3.1.0 · macOS 14+ · Changelog · Source · SHA-256 ▾ Zip SHA-256 536BDA55F06E45BD7EDC6CBED29AEB230DB0F003675388A78F45D714A9CA8705



What makes TaskExplorer great:
  • Live, via Endpoint Security
    A system extension now monitors the system, so processes appear the moment they start and vanish when they exit, and their dylibs, files, and connections are refreshed as they change. No more password prompt on every launch.

  • Built-in AI assistant
    Ask questions such as "what's listening on the network?" or "which processes are ad-hoc signed?" The assistant queries TaskExplorer's live data (and can drive the UI), and runs on-device via Apple Intelligence, or with your own Claude or ChatGPT API key.

  • Modern UI
    A filter field with #keyword tokens (including #everything, which searches dylibs, files, and connections too), a tree or flat process view, an inspector pane with full details for the selected item, and anything VirusTotal flags shown in red.

  • Shared cache dylibs
    Dylibs that live in the dyld shared cache can be shown per process, or indexed for every process so they show up in searches.

  • Export
    Save all processes, dylibs, files, and connections as JSON, from the app or from the command line.

Requirements:
macOS 14 (Sonoma) or newer, on Apple silicon or Intel. The on-device assistant additionally needs macOS 26 with Apple Intelligence enabled (Apple silicon only); on older systems the assistant works with a Claude or ChatGPT key.

Looking for an older version? TaskExplorer 2.1.0 supports macOS 11 to 13.

Installing TaskExplorer

Download and unzip the archive, then move TaskExplorer.app to /Applications (apps with a system extension must run from there; launched from elsewhere, TaskExplorer offers to move itself).

The first time you run TaskExplorer, a short welcome walks you through what it does and the permissions it needs:


Because TaskExplorer uses Apple's Endpoint Security framework to monitor processes, it needs two permissions, both granted in System Settings. The 'Permissions' page tracks each one, and shows an 'Open System Settings…' button wherever your approval is needed:
  • System extension: macOS asks you to allow the extension the first time it is loaded. Open System Settings › General › Login Items & Extensions, and allow "TaskExplorer".

  • Full Disk Access: the extension needs this to read every process and file. Open System Settings › Privacy & Security › Full Disk Access, and enable "TaskExplorer Extension".

Next, you can optionally enter API keys.


A (free) VirusTotal key lets TaskExplorer flag known malware.

TaskExplorer's assistant runs on-device with Apple Intelligence and needs no key. If you'd rather use a more powerful assistant (Claude or ChatGPT), add your own Anthropic or OpenAI key.

Everything here is optional, is stored securely in your keychain, and can be added or changed later in Settings.

That's it! Click 'Start' and TaskExplorer will enumerate everything that's running:


Using TaskExplorer

The main window has three parts: the process list on top, a pane below it showing the selected process's dylibs, files, or network connections, and an inspector on the right with full details for whatever is selected. The AI assistant lives in a sidebar on the left (toggled with the sidebar button in the toolbar).


The process list shows every running process: its icon, name, and path, its pid, the user it runs as, its code signing status (Apple, Developer ID, ad-hoc, or unsigned), and its VirusTotal result. Processes are added and removed live as they start and exit. Processes flagged by VirusTotal, and processes that have a flagged dylib loaded, are shown in red. The toolbar buttons (top right) switch between a flat list and a hierarchical tree of parent and child processes, show or hide the inspector, and (the '#' menu) list the keyword filters.

The bottom pane shows, for the selected process, its loaded dylibs, its open files, or its network connections. Use the Dylibs / Files / Network control to switch (or the View menu). Each pane has its own filter field on the right, and dylibs show which team ID signed them and how many processes have them loaded:



Most dylibs on a modern Mac are not on disk but in the dyld shared cache. By default these are enumerated for the selected process when you tick 'Include shared cache dylibs'. To have them attributed to every process (so that global search and the assistant can answer "which processes load X"), enable indexing in Settings (see below); this runs in the background and takes a few minutes. As vmmap briefly suspends the process it inspects, it is never run on Endpoint Security clients, core system daemons, or TaskExplorer itself: those list only their dylibs mapped from disk.

The inspector shows everything TaskExplorer knows about the selected item. For a process: its path and arguments, user, parent and children, start time, hashes, and full code signing details (signer, team ID, and any signing issues), plus its VirusTotal result. For a dylib or file: the same binary details, and the list of processes it is loaded in (or opened by). For a connection: protocol, addresses, ports, interface, and state.


The status bar at the bottom shows whether live monitoring is active and how many processes are running. The 'Save' button exports everything (all processes with their dylibs, files, and connections) as a JSON file.

Searching and Filtering

The filter field in the toolbar narrows the process list as you type: text matches a process's name, path, or pid. Typing a #keyword (or picking one from the '#' menu next to the field) adds a filter token; tokens can be combined, and combined with text. Press Esc to clear everything.


The available keywords:
  • #everything — search dylibs, files, and connections too (see below)
  • #3rdparty — not signed by Apple
  • #adhoc — ad-hoc signed (no certificate)
  • #flagged — flagged by VirusTotal
  • #unknown — unknown to VirusTotal
  • #obfuscated — packed or encrypted binary
  • #network — processes with network connections
  • #listening — processes with listening sockets
  • #root — processes running as root
Note:
Version 3 uses your own (free) VirusTotal API key, so lookups count against your quota rather than a shared one. Get one at virustotal.com. Only file hashes are sent to VirusTotal; never the files themselves. Flagged items are shown in red, filtered with #flagged, and listed together via View › Flagged Items….

The same keywords work in the bottom pane's filter field (where applicable: for example #adhoc applies to dylibs, but not to files).

To search across everything at once, add the #everything token: type it, or pick 'Search everything' from the '#' menu. The search then covers dylibs, files, and network connections as well as processes, and can be combined with other keywords. Results are grouped by kind; click any result to select it in the main window, and press 'Done' (or remove the token) to return to the process list:


The AI Assistant

New in version 3, the sidebar hosts an assistant that can answer questions about what's running on your Mac. It is given a set of tools that query TaskExplorer's live data (processes, dylibs, files, connections, VirusTotal results, and the #keyword filters), plus a few that drive the UI (select a process, set a filter, switch the view or the bottom tab).


Pick a provider with the menu at the top of the sidebar:
  • Apple Intelligence (the default, where available)
    Runs entirely on-device via Apple's Foundation Models: no account, no key, and nothing leaves your Mac. Requires macOS 26 with Apple Intelligence turned on. The on-device model is small, so it works best with focused questions, and long lists are paged ("showing 30 of 62"); for exhaustive listings, use the filter field instead.

  • Claude or ChatGPT
    Use your own Anthropic or OpenAI API key (entered in Settings, stored in your keychain). These models are far more capable for open-ended analysis. Note that whatever the assistant queries (process names, paths, and command lines) is sent to the provider you select.
Some things to try: "What processes are running as root?", "What processes are using the network?", "What 3rd-party processes are running?", or "Show me everything Chrome has open".

Note:
Process names, paths, and arguments are controlled by whoever started the process, and the assistant is instructed to treat everything it reads as untrusted data, never as instructions. It only changes the UI when your own message asks it to. Still, treat its answers as a starting point for your own investigation, not a verdict.

Settings

Open Settings from the TaskExplorer menu (or press ⌘,):


  • VirusTotal: your API key, and a switch to pause lookups.

  • AI Assistant: whether Apple Intelligence is available on this Mac, and your Anthropic and OpenAI keys.

  • Dylibs: index the dyld shared cache for all processes. This runs vmmap on every process in the background (several minutes), so that shared cache dylibs are attributed to processes in global search and assistant queries.

Command Line

TaskExplorer can also be run from the command line, for example to programmatically enumerate or scan everything that's running. Execute the binary inside the application bundle with -h to see the options:
TASKEXPLORER USAGE:
 -h or -help  display this usage info
 -explore     enumerate all tasks and dylibs (JSON)
 -scan        list tasks and dylibs flagged by VirusTotal (JSON; requires an API key)

options:
 -pid [pid]   just the specified task
 -detailed    for each task, include its dylibs, files, & network connections
 -apple       include Apple (platform) tasks in '-explore' output (default: 3rd-party only)
 -key [key]   VirusTotal API key (default: the key saved via the app's Settings)
 -skipVT      don't query VirusTotal ('-explore' only)
 -pretty      pretty-print the JSON

note: requires TaskExplorer's system extension to be installed & approved (run the app once)

Note:
Unlike earlier versions, the command line no longer needs to run as root: it talks to the system extension, so just run the app once to get the extension installed and approved. Output is JSON on STDOUT (with numbers and booleans as such), so simply redirect it to a file:

$ /Applications/TaskExplorer.app/Contents/MacOS/TaskExplorer -explore -detailed -pretty > ~/tasks.json

Uninstalling TaskExplorer

Choose 'Uninstall TaskExplorer…' from the TaskExplorer menu. This deactivates the system extension (macOS will ask for your password to authorize this), removes TaskExplorer's settings and API keys from your keychain, and moves the app to the Trash.

FAQs

Question: Why does TaskExplorer need a system extension and Full Disk Access?
Version 3 uses Apple's Endpoint Security framework to see processes start and exit, and to inspect them (loaded dylibs, open files, connections) without running the app as root. Apple requires Endpoint Security clients to run as a system extension, and requires that extension to have Full Disk Access. Earlier versions instead asked for your password at every launch.

Question: The assistant says Apple Intelligence isn't available. Why?
The on-device model needs macOS 26 or newer, an Apple silicon Mac, and Apple Intelligence turned on in System Settings › Apple Intelligence & Siri (the first time, macOS downloads the model in the background, which can take a while). On any other system, the assistant works with a Claude or ChatGPT key.

Question: What does TaskExplorer send off my Mac?
Nothing, unless you opt in:
  • VirusTotal: if you add a VirusTotal API key, the hashes of binaries (never the files themselves) are sent to VirusTotal to check for known malware.
  • AI assistant: with Apple Intelligence (the default), everything stays on your Mac. If you instead select Claude or ChatGPT, your questions, along with the data the assistant looks up to answer them (process names, paths, arguments, signing info, etc.), are sent to Anthropic or OpenAI, via your own API key.
  • Updates: 'Check for Updates…' fetches a version file from objective-see.com. Nothing about you or your Mac is sent.