willyu-elastic / SimpleEndpoint
Sample code for macOS Extensions Part 3
☆24Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for SimpleEndpoint
- MacOS X process monitor using EndpointSecurity extension.☆33Updated 3 years ago
- Mac OS X file system filter to redirect file operations☆41Updated 6 years ago
- A TrustedBSD module to control execution of binaries with suid bit set☆37Updated 10 years ago
- macOS XProtect definition files☆38Updated 2 years ago
- A file system filter for Mac OS X☆99Updated 7 years ago
- Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.☆71Updated 8 months ago
- macOS application that makes use of the EndpointSecurity framework☆18Updated 5 years ago
- A macOS IOKit objects hooker☆86Updated 7 years ago
- A MacOS VFS isolation layer to redirect file I/O operations.☆28Updated 6 years ago
- This is a complete Xcode project of the Endpoint Security Demo gist: https://gist.github.com/Omar-Ikram/8e6721d8e83a3da69b31d4c2612a68ba☆19Updated 2 years ago
- macOS Private KPI Symbol Resolver☆49Updated 7 years ago
- Tool for reverse-engineering Apple's sandbox☆55Updated 7 years ago
- Mac OS X syscall hook kext☆22Updated 8 years ago
- ☆65Updated 2 years ago
- A macOS behavior audit / event monitoring system with scope of file, process and network events (based on Endpoint Security Framework).☆43Updated 5 months ago
- Learn MacOS kernel extensions☆46Updated 7 years ago
- macOS notes☆113Updated 5 years ago
- A B-Tree sparse file implementation for kernel mode IOKit modules/extensions.☆15Updated 7 years ago
- Dump Kext information from Macos. Support batch analysis. The disassembly framework used is Capstone☆43Updated 7 years ago
- A MacOS network kernel extension filter for IPv4/IPv6 sockets.☆74Updated 7 years ago
- A library to execute code in the context of other processes on iOS 11.☆80Updated 6 years ago
- A Mac OS X kernel mode filter driver ( a kernel extension ) for devices, file systems and network☆166Updated 6 years ago
- A collection of CVE POC code☆11Updated 5 years ago
- ☆91Updated last year
- Git repository to browse the XNU releases from☆10Updated 3 years ago
- Updated sample code for OS X and iOS Kernel Programming book☆35Updated 5 years ago
- OSX Events Monitor☆21Updated 6 years ago
- A tool for Mac OS X proxy kext generation to export kernel symbols☆25Updated 6 years ago
- App sandbox escapes for macOS☆28Updated 4 years ago
- A module to expose the Endpoint Security library to Swift☆20Updated 5 years ago