wowsignal-io / pedroLinks
Pipeline EDR Observer - A lightweight, open source EDR for Linux
☆16Updated 3 weeks ago
Alternatives and similar repositories for pedro
Users that are interested in pedro are comparing it to the libraries listed below
Sorting:
- A cross platform parser for Apple UnifiedLogs!☆290Updated last month
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆76Updated last year
- Mapping XProtect's obfuscated malware family names to common industry names.☆89Updated last week
- machofile is a module to parse Mach-O binary files☆89Updated 3 months ago
- Aftermath is a free macOS IR framework☆552Updated last month
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆266Updated last year
- A binary and file access authorization system for macOS.☆427Updated this week
- A tool to run and validate telemetry for Atomic Red Team tests☆15Updated last year
- Generate Volatility3 profiles from BTF.☆29Updated 10 months ago
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆97Updated 3 years ago
- A ruleset to find potentially malicious code in macOS malware samples☆41Updated 2 years ago
- macOS Endpoint Security Message Analysis Tool☆47Updated 3 years ago
- A parser for Unified logging tracev3 files☆95Updated 3 months ago
- A companion Github repo for the book - Threat Hunting macOS by Jaron Bradley☆13Updated 3 months ago
- Parser fo macOS/iOS FSEvents Logs☆38Updated last year
- Forensic toolkit for iOS sysdiagnose feature☆237Updated this week
- Red Canary's eBPF Sensor☆111Updated 5 months ago
- ☆28Updated last year
- ☆54Updated last year
- A minimal malware analysis sandbox for macOS☆34Updated 2 years ago
- ELEGANTBOUNCER is a detection tool for file-based mobile exploits.☆156Updated last month
- Rust Bindings for Endpoint Security☆32Updated last week
- Yet another fseventsd parser for macOS forensics☆11Updated last year
- This is a little plugin to copy disassembly in a way that is usable in YARA rules!☆47Updated 7 months ago
- DFIQ is a collection of investigative questions and the approaches for answering them☆294Updated 9 months ago
- Aftermath is a free macOS incident response framework☆34Updated last month
- Detection rules to look for Log4J usage and exploitation☆18Updated 4 months ago
- Persistent Certificate Store (PCeS) is a certificate lifecycle management system written in Go.☆20Updated last week
- ☆51Updated last month
- A module to expose the Endpoint Security library to Swift☆20Updated 6 years ago