ald3ns / XPR-dump
Helper scripts to automate the extraction of YARA rules from XProtectRemediators
☆18Updated 11 months ago
Alternatives and similar repositories for XPR-dump:
Users that are interested in XPR-dump are comparing it to the libraries listed below
- Software installation scripts for macOS systems that allows you to setup a Virtual Machine (VM) for reverse engineering macOS malware☆30Updated last month
- A Ghidra extension for reverse-engineering macOS binaries.☆17Updated last month
- Enumerate Location Services using CoreLocation API on macOS☆18Updated 3 years ago
- ☆31Updated 8 months ago
- Discover which process execute a hunted binary inside macOS☆24Updated 3 years ago
- Repository for Flare-On challenges and solutions/code☆9Updated 2 months ago
- machofile is a module to parse Mach-O binary files☆48Updated last year
- ☆45Updated 7 months ago
- ESF modular ingestion tool for development and research.☆34Updated 3 years ago
- Tools for macOS Forensic Bootable media☆15Updated 4 years ago
- Swift code to run a dylib on disk☆15Updated 2 years ago
- GreenLambert macOS IDA plugin to deobfuscate strings☆12Updated 3 years ago
- ☆86Updated 4 months ago
- ☆13Updated 4 years ago
- IDA plugin that resolves PPL calls to the actual underlying PPL function.☆57Updated last year
- My collection of PoCs☆25Updated last year
- Utilities for working with vivisect☆25Updated last month
- A IDA plugin to enable linking to locations in an IDB with a disas:// URI☆32Updated last year
- A minimal malware analysis sandbox for macOS☆28Updated 2 years ago
- Swift implementation of in-memory Mach-O loading on macOS☆61Updated 2 years ago
- Kernel Cache Decryption for iOS☆14Updated 3 years ago
- One-Click to Completely Take Over A macOS Device☆17Updated 2 years ago
- DeepToad is a library and a tool to clusterize similar files using fuzzy hashing☆20Updated 4 years ago
- macOS codesigning translocation vulnerability.☆42Updated 3 years ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated last year
- Code lifting for executing a visionOS library os macOS using QBDL and QBDI☆15Updated 4 months ago
- ☆18Updated 4 years ago
- PoC multi-layer protector for ELF32 x86 binaries☆10Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- PoC of macho loading from memory☆53Updated 2 months ago