A ruleset to find potentially malicious code in macOS malware samples
☆41Aug 29, 2023Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Rules Shared by the Community from 100 Days of YARA 2023 -☆18Apr 10, 2023Updated 3 years ago
- List of legitimate macOS apps doing not great things☆35Feb 11, 2022Updated 4 years ago
- Conceptual Methods for Finding Commonalities in Macho Files☆12Mar 21, 2024Updated 2 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆48Apr 14, 2025Updated last year
- machofile is a module to parse Mach-O binary files☆96Feb 10, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Oct 3, 2023Updated 2 years ago
- Desktop application for MacOS calling Microsoft Graph. It's written in swift and uses the Microsoft identity platform☆12Jan 12, 2024Updated 2 years ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆26Mar 25, 2021Updated 5 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- ☆19Aug 4, 2021Updated 4 years ago
- Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS or GCP.☆27Apr 19, 2026Updated 2 weeks ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated 10 months ago
- macOS Endpoint Security Message Analysis Tool☆47Jan 31, 2022Updated 4 years ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆41Oct 29, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆21Nov 7, 2023Updated 2 years ago
- Golang Tool to interact with Launchd and other services with XPC☆29May 7, 2020Updated 6 years ago
- macOS Security Research☆123Mar 15, 2024Updated 2 years ago
- A cross platform parser for Apple UnifiedLogs!☆347Updated this week
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆82Nov 21, 2023Updated 2 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆67Feb 1, 2024Updated 2 years ago
- Mach-O file format reader, written entirely in Swift☆13May 10, 2020Updated 5 years ago
- Backup☆10Oct 6, 2025Updated 7 months ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆125Apr 14, 2026Updated 3 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆36Jun 1, 2023Updated 2 years ago
- ☆14Oct 24, 2024Updated last year
- ☆12Jun 22, 2022Updated 3 years ago
- A malware scanner with Yara and ClamAV binding☆12Apr 16, 2025Updated last year
- ☆65May 21, 2024Updated last year
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆525Dec 22, 2025Updated 4 months ago
- Parser fo macOS/iOS FSEvents Logs☆46May 6, 2024Updated 2 years ago
- A PowerShell Module Dedicated to Reverse Engineering☆15Jan 17, 2020Updated 6 years ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆67Jul 1, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Aftermath is a free macOS IR framework☆580Sep 25, 2025Updated 7 months ago
- Presentation materials for talks I've given.☆20Oct 14, 2019Updated 6 years ago
- Exploit for CVE-2023-38571☆14Sep 27, 2023Updated 2 years ago
- Public Maltego Transforms☆24May 24, 2017Updated 8 years ago
- God Mode Detection Rules☆132Aug 8, 2024Updated last year
- Malware that we analyzed on our site.☆26Nov 12, 2025Updated 5 months ago
- Collection of Slides From My Conference Talks☆21Nov 21, 2022Updated 3 years ago