A ruleset to find potentially malicious code in macOS malware samples
☆40Aug 29, 2023Updated 3 years ago
Alternatives and similar repositories for macos-ttps-yara
Users that are interested in macos-ttps-yara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Mapping XProtect's obfuscated malware family names to common industry names.☆94Updated this week
- machofile is a module to parse Mach-O binary files☆99Feb 10, 2026Updated 6 months ago
- Conceptual Methods for Finding Commonalities in Macho Files☆13Mar 21, 2024Updated 2 years ago
- Desktop application for MacOS calling Microsoft Graph. It's written in swift and uses the Microsoft identity platform☆13Jan 12, 2024Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023 -☆19Apr 10, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- A practical DFIR cheatsheet for identifying, collecting, triaging, and reviewing macOS persistence mechanisms, with acquisition-aware gui…☆25Apr 26, 2026Updated 4 months ago
- ☆19Aug 4, 2021Updated 5 years ago
- ☆57Jul 1, 2024Updated 2 years ago
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated last year
- Track Apple software update changes with Github Actions☆28Feb 11, 2022Updated 4 years ago
- macOS Endpoint Security Message Analysis Tool☆48Jan 31, 2022Updated 4 years ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆41Oct 29, 2024Updated last year
- ☆20Nov 7, 2023Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Golang Tool to interact with Launchd and other services with XPC☆28May 7, 2020Updated 6 years ago
- Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS or GCP.☆27Apr 19, 2026Updated 4 months ago
- macOS Security Research☆122Mar 15, 2024Updated 2 years ago
- A malware scanner with Yara and ClamAV binding☆12May 23, 2026Updated 3 months ago
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆83Nov 21, 2023Updated 2 years ago
- Mach-O file format reader, written entirely in Swift☆13May 10, 2020Updated 6 years ago
- Yara rules written by me, for free use.☆20Nov 26, 2021Updated 4 years ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆67Feb 1, 2024Updated 2 years ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆125Apr 14, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆16Oct 24, 2024Updated last year
- ☆12Jun 22, 2022Updated 4 years ago
- A PowerShell Module Dedicated to Reverse Engineering☆15Jan 17, 2020Updated 6 years ago
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆36Jun 1, 2023Updated 3 years ago
- ☆66May 21, 2024Updated 2 years ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆541May 14, 2026Updated 3 months ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆70Jul 1, 2020Updated 6 years ago
- JXA situational awareness helper by simply reading specific files on a filesystem☆82Feb 17, 2026Updated 6 months ago
- Exploit for CVE-2023-38571☆13Sep 27, 2023Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Aftermath is a free macOS IR framework☆595Sep 25, 2025Updated 11 months ago
- Detection tells you a key is real; geiger tells you whether it's dangerous.☆36Updated this week
- God Mode Detection Rules☆137Aug 8, 2024Updated 2 years ago
- Public Maltego Transforms☆24May 24, 2017Updated 9 years ago
- BinjaryNinja plugin for a ShellStorm like assembly/disassembly experience☆17Jul 28, 2026Updated last month
- Scripts and tools used by Ping Identity's corporate IT organisation☆13Sep 6, 2023Updated 3 years ago
- Malware that we analyzed on our site.☆26Aug 4, 2026Updated last month