Mac Gems: Automatic Launch Object Detection lets you track background processes

When you’re using your Mac, currently running applications appear in the Dock, but there are many processes running invisibly in the background. Some of these are processes you’ve initiated yourself—for example, by adding them to the Login Items list in System Preferences—but others are running because the OS or some installer set them up to run in the background, either continuously or on a schedule. Specifically, many of these processes are controlled by an OS X feature called launchd, which uses special configuration files to determine which processes should be run, and when.

Many of these processes are good, and some are even necessary. For example, some backup programs use them to make sure your scheduled backups run at the appropriate time(s). But I personally want to know when an app or an installer sets up a new background process. Partly because I like to know as much about what’s going on with my Mac as possible, but also because as useful as the launchd system is, it can also be used for nefarious purposes: Someone with less-than-honorable intentions can use it to launch, or to keep running, malware or spyware.

How do you know when one of these background processes—in other words, a new launchd configuration file—is added? One solution is a clever utility called Automatic Launch Object Detection (ALOD for short), created by the Computer Incident Response Center Luxembourg (CIRCL). This utility monitors all the locations that launchd configuration files (and other types of background programs) are stored:

  • ~/Library/LaunchAgents
  • /Library/LaunchAgents
  • /Library/LaunchDaemons
  • /System/Library/LaunchAgents
  • /System/Library/LaunchDaemons
  • /Library/StartupItems
  • /System/Library/StartupItems
ALOD's alert message

When a change to the contents of one of these folders is detected, ALOD displays an alert similar to the one you see here, noting which folder has gained a new configuration file; it also offers to show you the newly added item(s). Click Yes, and ALOD opens the folder and selects the newly added file(s).

I call ALOD clever because it does its thing by using features built in to OS X: AppleScript and Folder Actions. The utility itself is a simple AppleScript that displays the aforementioned dialog and takes you to the appropriate folder. The ALOD installer confirms that OS X’s Folder Actions feature is enabled, installs the AppleScript (called add - new item alert without timeout.scpt) in your personal Folder Action Scripts folder (in ~/Library/Scripts), and then attaches the script to the seven folders listed above. When the contents of one of those folders changes, OS X’s Folder Actions feature passes information about that change to the ALOD Macworld | Server Error

500 - Server Error

Oops! We're not able to find the page you're looking for. Here are some options to help you get back on the right track:

If all else has failed, try emailing our friendly customer service staff.