its-a-feature / offensive_macos
Tracking of offensive macOS tooling, blogs, and related helpful information
☆161Updated 3 months ago
Alternatives and similar repositories for offensive_macos:
Users that are interested in offensive_macos are comparing it to the libraries listed below
- Collection of macOS persistence methods and miscellaneous tools in JXA☆269Updated last year
- Swift 5 macOS agent☆101Updated 7 months ago
- macOS Initial Access Payload Generator☆303Updated last year
- Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.☆106Updated 2 years ago
- Objective-C library and console to interact with Heimdal APIs for macOS Kerberos☆146Updated last year
- ☆97Updated 4 years ago
- JXA situational awareness helper by simply reading specific files on a filesystem☆75Updated 3 years ago
- JavaScript for Automation (JXA) tool to do Active Directory enumeration.☆101Updated 3 years ago
- Interact with Chromium-based browsers' debug port to view open tabs, installed extensions, and cookies☆166Updated last year
- Payload designed for targeting Jamf enrolled devices.☆37Updated last year
- macOS persistence tool☆222Updated 3 years ago
- JXA and swift code that can perform some macOS situational awareness without generating TCC prompts.☆38Updated 2 years ago
- A macOS enumeration tool inspired by harmjoy's Windows-based Seatbelt enumeration tool. Author: Cedric Owens☆330Updated 2 years ago
- macOS Offensive Tools☆265Updated last year
- JavaScript for Automation (JXA) macOS agent☆71Updated 3 weeks ago
- Slackhound allows red and blue teams to perform fast reconnaissance on Slack workspaces/organizations to quickly search user profiles, lo…☆78Updated last year
- A repo to support the book☆106Updated 3 years ago
- ObjectiveC CLI tool for interacting with macOS Keychain☆77Updated 2 years ago
- A Red Team tool for exfiltrating sensitive data from Confluence pages.☆108Updated 2 years ago
- Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedri…☆120Updated 4 years ago
- JXA script to allow programmatic persistence via macOS Calendar.app alerts.☆42Updated 4 years ago
- A proof of concept for a clickjacking attack on macOS.☆94Updated last year
- JXA implementation of some SwiftBelt functions. Author: Cedric Owens☆43Updated last year
- ☆115Updated 3 years ago
- Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens☆46Updated 3 years ago
- LDAP Querying without the Suck☆99Updated 4 months ago
- ☆177Updated 3 months ago
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆95Updated 2 years ago
- ☆188Updated 2 years ago
- A tool to find folders excluded from AV real-time scanning using a time oracle☆232Updated last year