nsacyber / netfil
A kernel network manager with monitoring and limiting capabilities for macOS. #nsacyber
☆107Updated 8 years ago
Alternatives and similar repositories for netfil:
Users that are interested in netfil are comparing it to the libraries listed below
- A userland network manager with monitoring and limiting capabilities for macOS. #nsacyber☆77Updated 8 years ago
- monitor macOS for malicious activity☆233Updated 2 months ago
- A MacOS network kernel extension filter for IPv4/IPv6 sockets.☆75Updated 7 years ago
- The current repository contains all the scripts needed to build kernel-mode mac-a-mal malicious activity hooking on macOS.☆84Updated 6 years ago
- A kernel extension to mitigate Gatekeeper bypasses☆49Updated 9 years ago
- process info/monitoring library for macOS☆420Updated 4 years ago
- example project, utilizing Proc Info library☆70Updated 4 years ago
- OpenBSM open audit implementation☆168Updated 5 months ago
- Apple's tcplognke code sample☆30Updated 8 years ago
- A Mac OS X kernel mode filter driver ( a kernel extension ) for devices, file systems and network☆169Updated 7 years ago
- Assesses CPU security of embedded devices. #nsacyber☆139Updated 8 years ago
- Every OS X/ macOS white paper☆114Updated 5 years ago
- sniff mouse and keyboard events☆221Updated 4 years ago
- Replay HTTP and HTTPS requests from a PCAP based on TLS Master Secrets.☆95Updated 3 years ago
- XNU Rootkit Framework☆127Updated 10 years ago
- Presentation Archives for my macOS and iOS Related Research☆249Updated last month
- OSX Events Monitor☆22Updated 6 years ago
- This is a malware analyzer for Mac OS X that extends the Cuckoo Sandbox project (https://cuckoosandbox.org/)☆22Updated 8 years ago
- ☆114Updated 7 years ago
- Identifies unexpected and prohibited certificate authority certificates on Windows systems. #nsacyber☆112Updated 8 years ago
- A proposed hardware-based method for stopping known memory corruption exploitation techniques. #nsacyber☆154Updated 7 years ago
- System Integrity Protection (SIP) bypass for OSX 10.11.1 - 10.11.2 - 10.11.3☆147Updated 9 years ago
- Parser for OSX/iOS FSEvents Logs☆247Updated 4 months ago
- A PoC Mach-O infector via library injection☆64Updated 12 years ago
- A TrustedBSD module to control execution of binaries with suid bit set☆37Updated 10 years ago
- IOHIDFamily 0day☆443Updated 2 years ago
- Kernel extension to disable anti-debug tricks and other useful XNU "features"☆215Updated 2 years ago
- A OS X crypto ransomware PoC☆87Updated 9 years ago
- ☆42Updated 8 years ago
- checks if an application is pristine (untampered) and from the official Mac App Store☆74Updated 4 years ago