wowsignal-io / pedroLinks
Pipeline EDR Observer - A lightweight, open source EDR for Linux
☆14Updated this week
Alternatives and similar repositories for pedro
Users that are interested in pedro are comparing it to the libraries listed below
Sorting:
- A cross platform parser for Apple UnifiedLogs!☆277Updated last month
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆77Updated last year
- Mapping XProtect's obfuscated malware family names to common industry names.☆87Updated last year
- machofile is a module to parse Mach-O binary files☆88Updated last month
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆262Updated last year
- Generate Volatility3 profiles from BTF.☆28Updated 8 months ago
- Aftermath is a free macOS IR framework☆535Updated 3 weeks ago
- A binary and file access authorization system for macOS.☆363Updated last week
- A tool to run and validate telemetry for Atomic Red Team tests☆14Updated last year
- DFIQ is a collection of investigative questions and the approaches for answering them☆292Updated 7 months ago
- Forensic toolkit for iOS sysdiagnose feature☆221Updated this week
- A ruleset to find potentially malicious code in macOS malware samples☆40Updated 2 years ago
- A parser for Unified logging tracev3 files☆93Updated last month
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆97Updated 2 years ago
- Red Canary's eBPF Sensor☆109Updated 3 months ago
- A minimal malware analysis sandbox for macOS☆31Updated 2 years ago
- ☆28Updated last year
- Rust Bindings for Endpoint Security☆29Updated 3 weeks ago
- macOS Endpoint Security Message Analysis Tool☆47Updated 3 years ago
- ELEGANTBOUNCER is a detection tool for file-based mobile exploits.☆138Updated this week
- convert ELF/DWARF symbol and type information into vol3's intermediate JSON☆133Updated 11 months ago
- ☆145Updated 3 weeks ago
- ☆51Updated last year
- ☆74Updated last month
- Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" ma…☆477Updated last month
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆117Updated 11 months ago
- Parser fo macOS/iOS FSEvents Logs☆38Updated last year
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access…☆72Updated this week
- Detect common classes of XPC exploits☆14Updated 9 months ago
- Forensic Artifact Collection Tool for macOS☆114Updated last month