Node.js中如何以非轮询方式监听其他进程启动事件并拦截黑名单应用
Great question! Polling the process list over and over is clunky and wastes system resources, so let’s dive into native, event-driven approaches tailored to each major operating system—plus how to trigger alerts when a blacklisted app fires up.
Windows: WMI Event Subscriptions
Windows’ Windows Management Instrumentation (WMI) lets you subscribe directly to process creation events, no polling required. Node.js packages make it easy to hook into this system.
Example with node-wmi
First, install the package:
npm install node-wmi
Then set up a listener for Win32_ProcessStartTrace events (these fire every time a new process launches):
const wmi = require('node-wmi'); const notifier = require('node-notifier'); // Your blacklist of target process names const BLACKLIST = ['badapp.exe', 'malicious.exe']; // Subscribe to process start events wmi.Query({ class: 'Win32_ProcessStartTrace', properties: ['ProcessName', 'ProcessId'] }, (err, results) => { if (err) throw err; results.forEach(event => { const processName = event.ProcessName; if (BLACKLIST.includes(processName)) { notifier.notify({ title: 'Blacklisted App Detected', message: `${processName} has started!`, sound: true // Play a system sound for immediate attention }); } }); });
Linux: Audit Framework
Linux’s auditd system is built for monitoring system-level events, including process creation. You can configure it to log process launches, then have Node.js listen to the log stream in real time.
Step 1: Set Up Auditd Rules
First, add a rule to track execve calls (the system call that starts processes):
sudo auditctl -a exit,always -F arch=b64 -S execve
(Add this line to /etc/audit/rules.d/audit.rules if you want the rule to persist after reboot.)
Step 2: Node.js Log Listener
Use child_process to tail the audit log and parse events:
const { spawn } = require('child_process'); const notifier = require('node-notifier'); const BLACKLIST = ['badapp', 'malicious']; // Tail the audit log (path may vary by distro) const auditTail = spawn('tail', ['-f', '/var/log/audit/audit.log']); auditTail.stdout.on('data', (data) => { const logLine = data.toString(); // Look for execve events and extract the process name if (logLine.includes('execve')) { const processMatch = logLine.match(/comm="([^"]+)"/); if (processMatch) { const processName = processMatch[1]; if (BLACKLIST.includes(processName)) { notifier.notify({ title: 'Blacklisted App Detected', message: `${processName} has started!`, icon: 'path/to/warning-icon.png' // Optional custom icon }); } } } }); auditTail.stderr.on('data', (err) => { console.error(`Audit log error: ${err}`); });
macOS: Endpoint Security Framework
macOS offers the Endpoint Security (ES) framework, a native API for monitoring system events like process launches. You’ll need a Node.js binding to interact with it, such as macos-endpoint-security.
Example with macos-endpoint-security
Note: This requires root privileges and works on macOS 10.15+. Install the package first:
npm install macos-endpoint-security
Then set up a listener for process launch events:
const { Client, EventType } = require('macos-endpoint-security'); const notifier = require('node-notifier'); const BLACKLIST = ['badapp', 'malicious']; const client = new Client(); // Subscribe to process execution events client.subscribe([EventType.ES_EVENT_TYPE_NOTIFY_EXEC], (event) => { const processName = event.process.executable.path.split('/').pop(); if (BLACKLIST.includes(processName)) { notifier.notify({ title: 'Blacklisted App Detected', message: `${processName} has started!`, sound: 'Basso' // macOS system sound }); } }); // Start the client (must run as root) client.start();
Key Notes
- Permissions: All these approaches require elevated privileges (root/admin) since they access system-level event data.
- Cross-Platform: There’s no one-size-fits-all package, but you can use conditional imports to load the correct implementation based on the user’s OS.
node-notifier: This package works across all major OSes to trigger system notifications—perfect for alerting users about blacklisted apps.
内容的提问来源于stack exchange,提问作者Alireza Safaeirad

