A ruleset to find potentially malicious code in macOS malware samples
☆41Aug 29, 2023Updated 2 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Rules Shared by the Community from 100 Days of YARA 2023 -☆18Apr 10, 2023Updated 2 years ago
- List of legitimate macOS apps doing not great things☆35Feb 11, 2022Updated 4 years ago
- Conceptual Methods for Finding Commonalities in Macho Files☆12Mar 21, 2024Updated 2 years ago
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆48Apr 14, 2025Updated 11 months ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆41Oct 3, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆25Mar 25, 2021Updated 5 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- ☆56Jul 1, 2024Updated last year
- Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS or GCP.☆27Jan 19, 2026Updated 2 months ago
- A triage data collection script for macOS☆29Nov 27, 2020Updated 5 years ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated 9 months ago
- Track Apple software update changes with Github Actions☆27Feb 11, 2022Updated 4 years ago
- macOS Endpoint Security Message Analysis Tool☆47Jan 31, 2022Updated 4 years ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆41Oct 29, 2024Updated last year
- NordVPN Special Discount Offer • AdSave on top-rated NordVPN 1 or 2-year plans with secure browsing, privacy protection, and support for for all major platforms.
- Golang Tool to interact with Launchd and other services with XPC☆29May 7, 2020Updated 5 years ago
- ☆21Nov 7, 2023Updated 2 years ago
- A cross platform parser for Apple UnifiedLogs!☆336Mar 8, 2026Updated 2 weeks ago
- Menubar app to show running servers on localhost☆13Jan 31, 2021Updated 5 years ago
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆80Nov 21, 2023Updated 2 years ago
- Yara rules written by me, for free use.☆20Nov 26, 2021Updated 4 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Feb 1, 2024Updated 2 years ago
- Mach-O file format reader, written entirely in Swift☆13May 10, 2020Updated 5 years ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆122Mar 18, 2026Updated last week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- Backup☆10Oct 6, 2025Updated 5 months ago
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆36Jun 1, 2023Updated 2 years ago
- ☆14Oct 24, 2024Updated last year
- A malware scanner with Yara and ClamAV binding☆12Apr 16, 2025Updated 11 months ago
- Welcome to the Pressidium® Yara Rules repository. This section contains a carefully curated collection of Yara rules specifically designe…☆16Nov 5, 2023Updated 2 years ago
- ☆65May 21, 2024Updated last year
- Parser fo macOS/iOS FSEvents Logs☆43May 6, 2024Updated last year
- A PowerShell Module Dedicated to Reverse Engineering☆15Jan 17, 2020Updated 6 years ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆67Jul 1, 2020Updated 5 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- JXA situational awareness helper by simply reading specific files on a filesystem☆82Feb 17, 2026Updated last month
- Aftermath is a free macOS IR framework☆570Sep 25, 2025Updated 6 months ago
- Presentation materials for talks I've given.☆20Oct 14, 2019Updated 6 years ago
- Exploit for CVE-2023-38571☆13Sep 27, 2023Updated 2 years ago
- ☆81Oct 2, 2025Updated 5 months ago
- Public Maltego Transforms☆24May 24, 2017Updated 8 years ago
- BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience☆17Nov 28, 2024Updated last year