diff --git a/pages/osx/opensnoop.md b/pages/osx/opensnoop.md new file mode 100644 index 000000000..e54bfd570 --- /dev/null +++ b/pages/osx/opensnoop.md @@ -0,0 +1,19 @@ +# opensnoop + +> Tool that tracks file opens on your system. + +- Print all file opens as they occur: + +`sudo opensnoop` + +- Track all file opens by a process by name: + +`sudo opensnoop -n {{process_name}}` + +- Track all file opens by a process by PID: + +`sudo opensnoop -p {{PID}}` + +- Track which processes open a specified file: + +`sudo opensnoop -f {{path/to/file}}`