jamf / aftermath
Aftermath is a free macOS IR framework
☆508Updated 5 months ago
Alternatives and similar repositories for aftermath
Users that are interested in aftermath are comparing it to the libraries listed below
Sorting:
- A repository for open-source resources created for use with or alongside Jamf Protect.☆200Updated last week
- A binary and file access authorization system for macOS.☆259Updated this week
- Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" ma…☆461Updated 5 months ago
- An osquery extension for endpoint engineers☆106Updated 2 months ago
- ☆243Updated last month
- AutoMacTC: Automated Mac Forensic Triage Collector☆540Updated 3 years ago
- Post-Infection Collection Toolkit☆95Updated 2 years ago
- ☆70Updated 3 years ago
- Production-ready detection & response queries for osquery☆567Updated last week
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆254Updated 8 months ago
- CIS Benchmarks for macOS Catalina☆122Updated 7 months ago
- Suite of tools to facilitate attacks against the Jamf macOS management platform.☆184Updated 4 years ago
- Swift binary that will change a local administrator password to a random generated password. Similar behavior to LAPS for Windows☆406Updated 2 months ago
- Mapping XProtect's obfuscated malware family names to common industry names.☆86Updated last year
- ☆100Updated 2 years ago
- A macOS authorization plugin that helps MDM administrators ensure valid FileVault keys are escrowed for all their Macs.☆235Updated 8 months ago
- A ruleset to find potentially malicious code in macOS malware samples☆40Updated last year
- A serverless sync server for Santa, built on AWS☆93Updated 5 months ago
- SOFA | A MacAdmin's Simple Organized Feed for Apple Software Updates☆240Updated this week
- Dorothy is a tool to test security monitoring and detection for Okta environments☆182Updated 9 months ago
- The CrowdStrike Falcon SDK for Python☆406Updated this week
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆286Updated this week
- Unleash the power of the Falcon Platform at the CLI☆117Updated this week
- MDM Related code, docs, scripts, snippets, thoughts, and musings.☆118Updated last month
- LotL RMM☆178Updated last month
- Pokes users about outstanding security risks found by Crowdstrike Spotlight or vmware Workspace ONE so they secure their own endpoint.☆28Updated last week
- Sublime rules for email attack detection, prevention, and threat hunting.☆306Updated this week
- A tool to help users with pre-existing devices enroll into MDM☆292Updated 9 months ago
- Repository of attack and defensive information for Business Email Compromise investigations☆251Updated this week
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆75Updated last year