A ruleset to find potentially malicious code in macOS malware samples
☆41Aug 29, 2023Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Mapping XProtect's obfuscated malware family names to common industry names.☆94Nov 14, 2025Updated 6 months ago
- Rules Shared by the Community from 100 Days of YARA 2023 -☆18Apr 10, 2023Updated 3 years ago
- Conceptual Methods for Finding Commonalities in Macho Files☆12Mar 21, 2024Updated 2 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆48Apr 14, 2025Updated last year
- machofile is a module to parse Mach-O binary files☆96Feb 10, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Desktop application for MacOS calling Microsoft Graph. It's written in swift and uses the Microsoft identity platform☆12Jan 12, 2024Updated 2 years ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆26Mar 25, 2021Updated 5 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- ☆19Aug 4, 2021Updated 4 years ago
- ☆57Jul 1, 2024Updated last year
- Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS or GCP.☆27Apr 19, 2026Updated last month
- A triage data collection script for macOS☆30Nov 27, 2020Updated 5 years ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated 11 months ago
- Track Apple software update changes with Github Actions☆27Feb 11, 2022Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆20Nov 7, 2023Updated 2 years ago
- Golang Tool to interact with Launchd and other services with XPC☆29May 7, 2020Updated 6 years ago
- macOS Security Research☆122Mar 15, 2024Updated 2 years ago
- Menubar app to show running servers on localhost☆13Jan 31, 2021Updated 5 years ago
- A cross platform parser for Apple UnifiedLogs!☆354May 7, 2026Updated 3 weeks ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆68Feb 1, 2024Updated 2 years ago
- Yara rules written by me, for free use.☆20Nov 26, 2021Updated 4 years ago
- Mach-O file format reader, written entirely in Swift☆13May 10, 2020Updated 6 years ago
- Backup☆10Oct 6, 2025Updated 7 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆36Jun 1, 2023Updated 2 years ago
- ☆15Oct 24, 2024Updated last year
- Welcome to the Pressidium® Yara Rules repository. This section contains a carefully curated collection of Yara rules specifically designe…☆18Nov 5, 2023Updated 2 years ago
- ☆66May 21, 2024Updated 2 years ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆531May 14, 2026Updated 2 weeks ago
- Parser fo macOS/iOS FSEvents Logs☆46May 6, 2024Updated 2 years ago
- A PowerShell Module Dedicated to Reverse Engineering☆15Jan 17, 2020Updated 6 years ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆67Jul 1, 2020Updated 5 years ago
- JXA situational awareness helper by simply reading specific files on a filesystem☆82Feb 17, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Aftermath is a free macOS IR framework☆583Sep 25, 2025Updated 8 months ago
- Presentation materials for talks I've given.☆20Oct 14, 2019Updated 6 years ago
- ☆83Oct 2, 2025Updated 7 months ago
- Public Maltego Transforms☆24May 24, 2017Updated 9 years ago
- BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience☆17Nov 28, 2024Updated last year
- God Mode Detection Rules☆133Aug 8, 2024Updated last year
- Swift code to run a dylib on disk☆16May 9, 2022Updated 4 years ago