gyunaev / macprocmon
MacOS X process monitor using EndpointSecurity extension.
☆35Updated 4 years ago
Alternatives and similar repositories for macprocmon:
Users that are interested in macprocmon are comparing it to the libraries listed below
- A macOS behavior audit / event monitoring system with scope of file, process and network events (based on Endpoint Security Framework).☆45Updated 3 months ago
- Sample code for macOS Extensions Part 3☆24Updated 5 years ago
- Updated sample code for OS X and iOS Kernel Programming book☆37Updated 6 years ago
- Tool for reverse-engineering Apple's sandbox☆56Updated 7 years ago
- Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.☆78Updated last year
- Learn MacOS kernel extensions☆46Updated 7 years ago
- Mac OS X file system filter to redirect file operations☆42Updated 7 years ago
- Misc llvm patches☆23Updated 3 years ago
- X-Monitor is an open-source, extensible event monitoring tool for macOS that provides security professionals with the ability to perform …☆19Updated 11 months ago
- arm64 and arm64e dylib injector☆31Updated last year
- slightly modified version of jonathan levins lsdtrip bin available at http://newosxbook.com/tools/lsdtrip.html☆19Updated last year
- ios kernel class tree☆23Updated 5 years ago
- Sniffing on port messages☆25Updated 8 years ago
- Mach-O file parser.☆54Updated this week
- A simple demonstration of the macOS Network Extension☆15Updated 3 years ago
- Swift implementation of in-memory Mach-O loading on macOS☆63Updated 2 years ago
- A kext to facilitate calling PE_enter_debugger on machines that don't respect Cmd-Ctrl-Opt-Shift-Esc☆15Updated 6 years ago
- App sandbox escapes for macOS☆28Updated 4 years ago
- Inject a DyLib to an existing Mach-O file☆23Updated 9 years ago
- Scripts were written by me☆19Updated last month
- do not debug me☆11Updated 5 years ago
- XPC and Friends (libxpc, launchd and soon xpc.framework)☆62Updated 6 months ago
- A collection of CVE POC code☆11Updated 5 years ago
- XNU kernel symbol resolver(kernel extension)☆12Updated 6 years ago
- Guessed headers of non-public Apple SDK☆26Updated 3 months ago
- A RootKit for macOS that can perform kernel read/write, hook kernel and userspace functions, set custom conditional breakpoints, etc☆23Updated 2 years ago
- Experiment to attempt to build Apple's dyld tools.☆63Updated 4 years ago
- This project injects into Hopper Disassembler and exposes core functionality via a local server. It can be used to create automations/too…☆16Updated 4 years ago
- A macOS IOKit objects hooker☆87Updated 8 years ago
- ☆13Updated 4 years ago