steven-michaud / SandboxMirror
Tool for reverse-engineering Apple's sandbox
☆56Updated 8 years ago
Alternatives and similar repositories for SandboxMirror:
Users that are interested in SandboxMirror are comparing it to the libraries listed below
- Checks macOS for Kernel Task Port. It may help detect intrusive kexts that would leak the kernel task.☆21Updated 2 years ago
- macOS Private KPI Symbol Resolver☆49Updated 8 years ago
- Reexport symbols for Mach-O and ELF☆38Updated 7 years ago
- Binary Format of iOS 13 Sandbox Profile Collection☆51Updated 5 years ago
- iOS10~iOS13 Edition) Dump Kext information from iOS kernel cache. Applicable to the kernel which dump from memory. The disassembly framew…☆20Updated 3 years ago
- Sniffing on port messages☆25Updated 8 years ago
- This tool will help to fix the Mach-O header of iOS kernel which dump from the memory. So that IDA or function symbol-related tools can l…☆23Updated 8 years ago
- Small util to discover OS X sysent via bruteforce☆33Updated 8 years ago
- Runtime code injection suite for exploring OS X process security☆37Updated 15 years ago
- macOS kext for host_special_port(4) patch☆88Updated last year
- Learn MacOS kernel extensions☆46Updated 7 years ago
- Utility to create tbd's off dylibs☆78Updated 4 years ago
- simple radare2 rap:// server☆25Updated 8 years ago
- Experiment to attempt to build Apple's dyld tools.☆63Updated 4 years ago
- Reverse engineered headers for Apples CoreSymbolication private framework; plus the set of test cases I used to validate it☆91Updated 11 years ago
- ios kernel class tree☆23Updated 5 years ago
- A macOS IOKit objects hooker☆88Updated 8 years ago
- A library to execute code in the context of other processes on iOS 11.☆82Updated 6 years ago
- DYLD shared cache loader for Hopper☆36Updated 8 years ago
- Experimental improvements to Objective-C analysis for Binary Ninja☆16Updated this week
- Radare2 plugin to parse modern iOS 64-bit kernel caches☆29Updated 6 years ago
- A Kext that can be used to disable Rootless in OS X El Capitan/macOS Sierra. You need to sign it OR use an exploit to make OS X load it.☆78Updated 5 years ago
- Apple's XNU automatically updated live.☆25Updated 3 years ago
- ☆34Updated 5 years ago
- A Mach-O Load Command deobfuscator.☆43Updated 3 years ago
- C Library for Apple Firmware (Amalgam)☆28Updated 3 years ago
- IDA plugin to extract Mach-O binaries located in the disassembly or data☆59Updated 5 years ago
- App sandbox escapes for macOS☆30Updated 4 years ago
- Extract and generate code based on name and type for mig func/arg/request&reply member etc, ideal helper for creating monitor, tracker, f…☆17Updated 6 years ago
- MacOS X process monitor using EndpointSecurity extension.☆35Updated 4 years ago