bradleyjkemp / sigma-esf
Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework
☆20Updated 4 years ago
Alternatives and similar repositories for sigma-esf:
Users that are interested in sigma-esf are comparing it to the libraries listed below
- A minimal malware analysis sandbox for macOS☆28Updated 2 years ago
- Parser fo macOS/iOS FSEvents Logs☆29Updated 9 months ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆68Updated 4 years ago
- A triage data collection script for macOS☆27Updated 4 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated last week
- machofile is a module to parse Mach-O binary files☆48Updated last year
- A small tool to easily mount APFS image on macOS for forensics.☆14Updated 4 years ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆91Updated last year
- Scripts for MacOS related tasks.☆18Updated 4 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆15Updated 11 months ago
- ☆20Updated last year
- Just Another broken Registry Parser (JARP)☆16Updated 8 months ago
- macOS Artifact Intelligence Tool☆13Updated 5 years ago
- JXA script for Mythic that prints the TCC.db☆15Updated 3 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆26Updated 2 years ago
- Use "Full Disk Access" permissions to read the contents of TCC.db and display it in human-readable format☆38Updated 3 years ago
- Yara rules☆20Updated last year
- Attempt to replicate the functions of auto_rip by Corey Harrell in Python.☆13Updated 6 months ago
- A happy place for detection engineers, purple teamers and threat hunters focusing on macOS.☆21Updated 2 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 3 years ago
- Yara rules written by me, for free use.☆18Updated 3 years ago
- Norimaci is a simple and lightweight malware analysis sandbox for macOS☆69Updated 4 years ago
- Queries for parsed spotlight database in sqlite☆11Updated 4 years ago
- macOS .DS_Store Parser☆66Updated 3 years ago
- Yara Based Detection Engine for web browsers☆47Updated 3 years ago
- A script to assist in processing forensic RAM captures for malware triage☆27Updated 4 years ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆23Updated this week
- A ruleset to find potentially malicious code in macOS malware samples☆39Updated last year
- NTFS file system specimens☆14Updated last year