macOS
brew install --cask truetreelocal Homebrew cask metadata
cask / rank 5122
Command-line tool for pstree-like output. Version 0.8 via Homebrew Cask; verified from local package data.
install
brew install --cask truetreelocal Homebrew cask metadata
overview
Command-line tool for pstree-like output
history
TrueTree is a small macOS command-line process-tree utility aimed at incident responders and threat hunters who need a more useful process ancestry view than ordinary PID/PPID output.
The project grew out of Jaron Bradley's February 2020 write-up of the 'TrueTree' concept: on macOS, launchd and XPC often make ordinary process trees look flat or misleading, so the tool uses additional operating-system process metadata to reconstruct more helpful ancestry.
Its README later documented platform drift: after macOS 11 introduced runningboardd behavior that changed parentage observations, TrueTree was updated to use Application Services for some true-parent discovery while accepting that some terminated parents can no longer be recovered.
TrueTree appears to have remained a specialist macOS security tool rather than a broad Unix replacement for pstree. Its Homebrew cask packaging made a compiled release easy to install on analyst Macs, while the GitHub project stayed compact and focused.
The tool is used from a root shell to print an enhanced process tree, optionally showing timestamps, parent-data sources, network information, or a standard PID/PPID tree for comparison.
In package-manager culture it is the kind of niche binary that belongs in a forensic or IR workstation bootstrap list: install it with Homebrew, run it during macOS triage, and compare its output with ps, Activity Monitor, and launchctl procinfo.
TrueTree matters to package nerds because it packages a very macOS-specific diagnostic idea as a single CLI. It is not a general-purpose process viewer; its value is that Homebrew users can install a purpose-built process-ancestry helper without compiling an Xcode project.
security posture
No matching local secret-handling manifest was found for truetree. Package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
TrueTree | binary | Homebrew cask binary | TrueTree |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/themittenmac/TrueTree
install metadata
| Package key | cask:truetree |
|---|---|
| Version | 0.8 |
| Package manager | Homebrew Cask |
| Package manager page | https://formulae.brew.sh/cask/truetree |
| Homepage | https://themittenmac.com/the-truetree-concept/ |
| Repository | https://github.com/themittenmac/TrueTree |
| Upstream docs | https://themittenmac.com/the-truetree-concept/ |
| Source archive | https://github.com/themittenmac/TrueTree/releases/download/V0.8/TrueTree.zip |
| SHA-256 | 10fcc907a053b8d89f31de2695a714f06732cc539b4af4f7cf22c0ce198b9098 |
| Download URL | https://github.com/themittenmac/TrueTree/releases/download/V0.8/TrueTree.zip |
| Bottle | not recorded |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew cask API |
|---|---|
| Tap | homebrew/cask |
| Full Token | truetree |
| Names |
|
| Artifacts | |
| Deprecated | no |
| Disabled | no |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.