mellow-hype / santa-linux
A proof-of-concept Linux clone of Santa, Google's binary authorization system for macOS
☆30Updated 2 years ago
Alternatives and similar repositories for santa-linux:
Users that are interested in santa-linux are comparing it to the libraries listed below
- Checks for tpm vulnerabilities☆36Updated last year
- Tools to measure an app's App Sandbox usage☆24Updated 4 years ago
- ☆31Updated 8 months ago
- The Art of Mac Malware☆37Updated last month
- Helper scripts to automate the extraction of YARA rules from XProtectRemediators☆18Updated 11 months ago
- macOS Endpoint Security Message Analysis Tool☆45Updated 3 years ago
- ☆25Updated last year
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆61Updated 3 years ago
- Golang Tool to interact with Launchd and other services with XPC☆29Updated 4 years ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 5 years ago
- macOS XProtect definition files☆40Updated 2 years ago
- LKRG bypass methods☆70Updated 5 years ago
- A minimal malware analysis sandbox for macOS☆28Updated 2 years ago
- crashmon - A LLDB Based replacement for CrashWrangler☆46Updated last year
- Apple's crashwrangler with support for Apple Silicon☆32Updated 4 years ago
- An eBPF detection program for CVE-2022-0847☆28Updated 2 years ago
- Armory Drive - USB encrypted drive with mobile unlock over BLE☆53Updated this week
- macOS codesigning translocation vulnerability.☆42Updated 3 years ago
- Discover which process execute a hunted binary inside macOS☆24Updated 3 years ago
- Nice (ish) bindings for the EndpointSecurity framework on macOS for Rust.☆20Updated last year
- ELEGANTBOUNCER is a detection tool for file-based mobile exploits.☆29Updated last year
- ☆13Updated 4 years ago
- A repository teaching bss/data segment exploitation techniques.☆13Updated 5 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 3 years ago
- sandbox demo☆12Updated last year
- machofile is a module to parse Mach-O binary files☆48Updated last year
- A Swift port of some of the original PersistentJXA projects by D00MFist. Original PersistentJXA repo: https://github.com/D00MFist/Persist…☆31Updated 3 years ago
- DeepToad is a library and a tool to clusterize similar files using fuzzy hashing☆20Updated 4 years ago
- Scripts to secure and harden Mac OS X☆31Updated 3 years ago