You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Node.js中如何以非轮询方式监听其他进程启动事件并拦截黑名单应用

Non-Polling Process Startup Monitoring in Node.js for Blacklist Notifications

Great question! Polling the process list over and over is clunky and wastes system resources, so let’s dive into native, event-driven approaches tailored to each major operating system—plus how to trigger alerts when a blacklisted app fires up.

Windows: WMI Event Subscriptions

Windows’ Windows Management Instrumentation (WMI) lets you subscribe directly to process creation events, no polling required. Node.js packages make it easy to hook into this system.

Example with node-wmi

First, install the package:

npm install node-wmi

Then set up a listener for Win32_ProcessStartTrace events (these fire every time a new process launches):

const wmi = require('node-wmi');
const notifier = require('node-notifier');

// Your blacklist of target process names
const BLACKLIST = ['badapp.exe', 'malicious.exe'];

// Subscribe to process start events
wmi.Query({
  class: 'Win32_ProcessStartTrace',
  properties: ['ProcessName', 'ProcessId']
}, (err, results) => {
  if (err) throw err;
  
  results.forEach(event => {
    const processName = event.ProcessName;
    if (BLACKLIST.includes(processName)) {
      notifier.notify({
        title: 'Blacklisted App Detected',
        message: `${processName} has started!`,
        sound: true // Play a system sound for immediate attention
      });
    }
  });
});

Linux: Audit Framework

Linux’s auditd system is built for monitoring system-level events, including process creation. You can configure it to log process launches, then have Node.js listen to the log stream in real time.

Step 1: Set Up Auditd Rules

First, add a rule to track execve calls (the system call that starts processes):

sudo auditctl -a exit,always -F arch=b64 -S execve

(Add this line to /etc/audit/rules.d/audit.rules if you want the rule to persist after reboot.)

Step 2: Node.js Log Listener

Use child_process to tail the audit log and parse events:

const { spawn } = require('child_process');
const notifier = require('node-notifier');

const BLACKLIST = ['badapp', 'malicious'];

// Tail the audit log (path may vary by distro)
const auditTail = spawn('tail', ['-f', '/var/log/audit/audit.log']);

auditTail.stdout.on('data', (data) => {
  const logLine = data.toString();
  // Look for execve events and extract the process name
  if (logLine.includes('execve')) {
    const processMatch = logLine.match(/comm="([^"]+)"/);
    if (processMatch) {
      const processName = processMatch[1];
      if (BLACKLIST.includes(processName)) {
        notifier.notify({
          title: 'Blacklisted App Detected',
          message: `${processName} has started!`,
          icon: 'path/to/warning-icon.png' // Optional custom icon
        });
      }
    }
  }
});

auditTail.stderr.on('data', (err) => {
  console.error(`Audit log error: ${err}`);
});

macOS: Endpoint Security Framework

macOS offers the Endpoint Security (ES) framework, a native API for monitoring system events like process launches. You’ll need a Node.js binding to interact with it, such as macos-endpoint-security.

Example with macos-endpoint-security

Note: This requires root privileges and works on macOS 10.15+. Install the package first:

npm install macos-endpoint-security

Then set up a listener for process launch events:

const { Client, EventType } = require('macos-endpoint-security');
const notifier = require('node-notifier');

const BLACKLIST = ['badapp', 'malicious'];

const client = new Client();

// Subscribe to process execution events
client.subscribe([EventType.ES_EVENT_TYPE_NOTIFY_EXEC], (event) => {
  const processName = event.process.executable.path.split('/').pop();
  if (BLACKLIST.includes(processName)) {
    notifier.notify({
      title: 'Blacklisted App Detected',
      message: `${processName} has started!`,
      sound: 'Basso' // macOS system sound
    });
  }
});

// Start the client (must run as root)
client.start();

Key Notes

  • Permissions: All these approaches require elevated privileges (root/admin) since they access system-level event data.
  • Cross-Platform: There’s no one-size-fits-all package, but you can use conditional imports to load the correct implementation based on the user’s OS.
  • node-notifier: This package works across all major OSes to trigger system notifications—perfect for alerting users about blacklisted apps.

内容的提问来源于stack exchange,提问作者Alireza Safaeirad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:04:28