HarfangLab / endpoint-secLinks
Rust Bindings for Endpoint Security
☆37Updated this week
Alternatives and similar repositories for endpoint-sec
Users that are interested in endpoint-sec are comparing it to the libraries listed below
Sorting:
- Rust bindings for VirusTotal/Yara☆80Updated 2 months ago
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆275Updated last year
- Mapping XProtect's obfuscated malware family names to common industry names.☆92Updated 2 months ago
- Rust bindings fo the Apple Silicon Hypervisor.framework☆47Updated 3 weeks ago
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆79Updated 2 years ago
- A cross platform parser for Apple UnifiedLogs!☆318Updated this week
- Basically a KrabsETW rip-off written in Rust☆82Updated 3 months ago
- A cross platform forensic parser written in Rust!☆101Updated last week
- Secure example of an XPC helper written in Swift☆108Updated 5 years ago
- An app to protect against process injection and suspicious file links on macOS☆230Updated 4 years ago
- A macOS behavior audit / event monitoring system with scope of file, process and network events (based on Endpoint Security Framework).☆50Updated 6 months ago
- Bindings to the macOS Security.framework☆286Updated 3 months ago
- ☆56Updated last year
- Pipeline EDR Observer - A lightweight, open source EDR for Linux☆19Updated last month
- Nice (ish) bindings for the EndpointSecurity framework on macOS for Rust.☆21Updated 2 years ago
- This is a complete Xcode project of the Endpoint Security Demo gist: https://gist.github.com/Omar-Ikram/8e6721d8e83a3da69b31d4c2612a68ba☆20Updated last year
- machofile is a module to parse Mach-O binary files☆90Updated this week
- macOS Endpoint Security Message Analysis Tool☆47Updated 4 years ago
- ELEGANTBOUNCER is a detection tool for file-based mobile exploits.☆171Updated 4 months ago
- Sample code for macOS Extensions Part 3☆24Updated 5 years ago
- Red Canary's eBPF Sensor☆113Updated 7 months ago
- Mach-O File Format Parser for Rust☆94Updated last year
- Framework definitions that allow to build a custom SIEM.☆28Updated last year
- macOS XProtect definition files☆40Updated 3 years ago
- MacOS X process monitor using EndpointSecurity extension.☆37Updated 4 months ago
- Tools to measure an app's App Sandbox usage☆26Updated 5 years ago
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆98Updated 3 years ago
- Helper scripts to automate the extraction of YARA rules from XProtectRemediators☆22Updated last year
- APFS filesystem format for Kaitai Struct☆82Updated 3 years ago
- An implementation of the NTFS filesystem in a Rust crate, usable from firmware level up to user-mode.☆581Updated 3 weeks ago