obelisk / endpointsecurity
Nice (ish) bindings for the EndpointSecurity framework on macOS for Rust.
☆20Updated last year
Alternatives and similar repositories for endpointsecurity:
Users that are interested in endpointsecurity are comparing it to the libraries listed below
- ☆31Updated 8 months ago
- A proof-of-concept Linux clone of Santa, Google's binary authorization system for macOS☆30Updated 2 years ago
- Helper scripts to automate the extraction of YARA rules from XProtectRemediators☆18Updated 11 months ago
- macOS XProtect definition files☆40Updated 2 years ago
- Tools to measure an app's App Sandbox usage☆24Updated 4 years ago
- Tools for macOS Forensic Bootable media☆15Updated 4 years ago
- ☆14Updated 6 years ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 5 years ago
- File Capability Extractor☆13Updated 3 months ago
- Discover which process execute a hunted binary inside macOS☆24Updated 3 years ago
- Grab functions from radare2☆10Updated 7 years ago
- macOS application that makes use of the EndpointSecurity framework☆19Updated 5 years ago
- The grey fox☆25Updated 8 years ago
- The Art of Mac Malware☆38Updated last month
- Swift implementation of in-memory Mach-O loading on macOS☆61Updated 2 years ago
- A collection of CVE POC code☆11Updated 5 years ago
- ☆18Updated last year
- A minimal malware analysis sandbox for macOS☆28Updated 2 years ago
- ☆42Updated 7 years ago
- excrypto offers specialized versions of the Go crypto, TLS, x509, and SSH packages designed for security research.☆11Updated this week
- machofile is a module to parse Mach-O binary files☆48Updated last year
- Rust bindings fo the Apple Silicon Hypervisor.framework☆32Updated 4 months ago
- ROP gadget finder and analysis in pure Javascript☆29Updated 2 years ago
- IDA plugin to Display Mach-O headers☆20Updated 13 years ago
- ☆21Updated 5 years ago
- Detect patterns of bad behavior in function calls☆25Updated 4 years ago
- Slack bot to assemble and disassemble using Capstone and Keystone☆11Updated 5 years ago
- Golang Tool to interact with Launchd and other services with XPC☆29Updated 4 years ago
- Use "Full Disk Access" permissions to read the contents of TCC.db and display it in human-readable format☆38Updated 3 years ago