A ruleset to find potentially malicious code in macOS malware samples
☆41Aug 29, 2023Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Mapping XProtect's obfuscated malware family names to common industry names.☆94Nov 14, 2025Updated 5 months ago
- Rules Shared by the Community from 100 Days of YARA 2023 -☆18Apr 10, 2023Updated 3 years ago
- Conceptual Methods for Finding Commonalities in Macho Files☆12Mar 21, 2024Updated 2 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆48Apr 14, 2025Updated last year
- machofile is a module to parse Mach-O binary files☆95Feb 10, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Oct 3, 2023Updated 2 years ago
- Desktop application for MacOS calling Microsoft Graph. It's written in swift and uses the Microsoft identity platform☆12Jan 12, 2024Updated 2 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- ☆19Aug 4, 2021Updated 4 years ago
- ☆57Jul 1, 2024Updated last year
- Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS or GCP.☆27Jan 19, 2026Updated 2 months ago
- A triage data collection script for macOS☆29Nov 27, 2020Updated 5 years ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated 9 months ago
- Track Apple software update changes with Github Actions☆27Feb 11, 2022Updated 4 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- macOS Endpoint Security Message Analysis Tool☆47Jan 31, 2022Updated 4 years ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆41Oct 29, 2024Updated last year
- Golang Tool to interact with Launchd and other services with XPC☆29May 7, 2020Updated 5 years ago
- ☆21Nov 7, 2023Updated 2 years ago
- macOS Security Research☆122Mar 15, 2024Updated 2 years ago
- A cross platform parser for Apple UnifiedLogs!☆340Mar 8, 2026Updated last month
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆81Nov 21, 2023Updated 2 years ago
- Yara rules written by me, for free use.☆20Nov 26, 2021Updated 4 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Feb 1, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Backup☆10Oct 6, 2025Updated 6 months ago
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆36Jun 1, 2023Updated 2 years ago
- ☆14Oct 24, 2024Updated last year
- ☆12Jun 22, 2022Updated 3 years ago
- A malware scanner with Yara and ClamAV binding☆12Apr 16, 2025Updated last year
- Welcome to the Pressidium® Yara Rules repository. This section contains a carefully curated collection of Yara rules specifically designe…☆16Nov 5, 2023Updated 2 years ago
- ☆65May 21, 2024Updated last year
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆517Dec 22, 2025Updated 3 months ago
- Parser fo macOS/iOS FSEvents Logs☆45May 6, 2024Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A PowerShell Module Dedicated to Reverse Engineering☆15Jan 17, 2020Updated 6 years ago
- Golang Shlyuz Implant Implementation☆13May 23, 2025Updated 10 months ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆67Jul 1, 2020Updated 5 years ago
- JXA situational awareness helper by simply reading specific files on a filesystem☆82Feb 17, 2026Updated last month
- Aftermath is a free macOS IR framework☆578Sep 25, 2025Updated 6 months ago
- Presentation materials for talks I've given.☆20Oct 14, 2019Updated 6 years ago
- ☆81Oct 2, 2025Updated 6 months ago