gyunaev / macprocmonLinks
MacOS X process monitor using EndpointSecurity extension.
☆35Updated 4 years ago
Alternatives and similar repositories for macprocmon
Users that are interested in macprocmon are comparing it to the libraries listed below
Sorting:
- Learn MacOS kernel extensions☆46Updated 7 years ago
- Tool for reverse-engineering Apple's sandbox☆58Updated 8 years ago
- Sample code for macOS Extensions Part 3☆24Updated 5 years ago
- A macOS IOKit objects hooker☆88Updated 8 years ago
- Updated sample code for OS X and iOS Kernel Programming book☆37Updated 6 years ago
- Mac OS X file system filter to redirect file operations☆42Updated 7 years ago
- A macOS behavior audit / event monitoring system with scope of file, process and network events (based on Endpoint Security Framework).☆47Updated 2 weeks ago
- Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.☆78Updated last year
- fG!'s crackme #1 source code☆35Updated 12 years ago
- A kext to facilitate calling PE_enter_debugger on machines that don't respect Cmd-Ctrl-Opt-Shift-Esc☆15Updated 6 years ago
- macOS notes☆118Updated 5 years ago
- Misc llvm patches☆23Updated 3 years ago
- macOS Private KPI Symbol Resolver☆49Updated 8 years ago
- Sniffing on port messages☆25Updated 8 years ago
- load macho files in memory without touching the Disk☆43Updated 2 years ago
- Inject a DyLib to an existing Mach-O file☆23Updated 9 years ago
- Modular binary injection framework☆18Updated 5 years ago
- A file system filter for Mac OS X☆101Updated 8 years ago
- A library to execute code in the context of other processes on iOS 11.☆82Updated 6 years ago
- do not debug me☆11Updated 6 years ago
- A collection of CVE POC code☆11Updated 5 years ago
- Cross Platform Hook Library based on Detours☆32Updated 9 months ago
- A tiny macOS 10.12 Sierra kernel extension for disabling CS_REQUIRE_LV system-wide☆73Updated 7 years ago
- A tool for debugging macOS virtual machines☆112Updated 4 years ago
- CVE-2018-4280: Mach port replacement vulnerability in launchd on macOS 10.13.5 leading to local privilege escalation and SIP bypass.☆59Updated 6 years ago
- Checks macOS for Kernel Task Port. It may help detect intrusive kexts that would leak the kernel task.☆22Updated 2 years ago
- Mach-O file parser.☆55Updated 2 months ago
- A collection of Hopper plugins and scripts☆27Updated 2 years ago
- Experimental improvements to Objective-C analysis for Binary Ninja☆40Updated this week
- A simple run-only applescript disassembler☆125Updated 3 years ago