rickmark / isafety
Toolset to examine iDevices for Security / Safety Threats
☆21Updated last year
Related projects ⓘ
Alternatives and complementary repositories for isafety
- macOS XProtect definition files☆38Updated 2 years ago
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆71Updated last year
- OSX Events Monitor☆21Updated 6 years ago
- macOS Endpoint Security Message Analysis Tool☆44Updated 2 years ago
- Research about malware that infects the EFI and SMC of Apple MacBooks.☆55Updated 8 months ago
- machofile is a module to parse Mach-O binary files☆48Updated 9 months ago
- A module to expose the Endpoint Security library to Swift☆20Updated 5 years ago
- A minimal malware analysis sandbox for macOS☆26Updated last year
- Tools to measure an app's App Sandbox usage☆23Updated 4 years ago
- The current repository contains all the scripts needed to build kernel-mode mac-a-mal malicious activity hooking on macOS.☆82Updated 6 years ago
- A Kext that can be used to disable Rootless in OS X El Capitan/macOS Sierra. You need to sign it OR use an exploit to make OS X load it.☆78Updated 4 years ago
- Use "Full Disk Access" permissions to read the contents of TCC.db and display it in human-readable format☆38Updated 3 years ago
- Some thingy that copies macOS specific forensic artifacts to the location where the script is run from and also generates some folders. B…☆14Updated 2 weeks ago
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆91Updated 2 years ago
- Helper scripts to automate the extraction of YARA rules from XProtectRemediators☆18Updated 8 months ago
- Integrity validator for iOS devices☆101Updated 5 years ago
- macOS application that makes use of the EndpointSecurity framework☆18Updated 5 years ago
- Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.☆71Updated 8 months ago
- Scripts to secure and harden Mac OS X☆31Updated 3 years ago
- ☆31Updated 5 months ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 4 years ago
- ☆37Updated 4 years ago
- Discover which process execute a hunted binary inside macOS☆24Updated 2 years ago
- An app to protect against process injection and suspicious file links on macOS☆218Updated 3 years ago
- Slides and resources for talks I've given☆47Updated last year
- ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings.☆34Updated last year
- Mapping XProtect's obfuscated malware family names to common industry names.☆82Updated 6 months ago
- example project, utilizing Proc Info library