ydkhatri / APFS_010Links
010 template for apfs
☆25Updated 4 years ago
Alternatives and similar repositories for APFS_010
Users that are interested in APFS_010 are comparing it to the libraries listed below
Sorting:
- OSX Events Monitor☆22Updated 6 years ago
- macOS XProtect definition files☆40Updated 3 years ago
- A (basic) Mach-O Library☆21Updated 3 years ago
- ☆31Updated 11 months ago
- Use "Full Disk Access" permissions to read the contents of TCC.db and display it in human-readable format☆39Updated 3 years ago
- Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.☆78Updated last year
- This is a work-in-progress command line tool for reversing run-only AppleScripts. It will help parse the output of applescript-disassembl…☆69Updated 4 years ago
- Research about malware that infects the EFI and SMC of Apple MacBooks.☆59Updated 2 months ago
- A tool for Mac OS X proxy kext generation to export kernel symbols☆26Updated 7 years ago
- Slides and material from my conference presentations☆16Updated last year
- Tools for macOS Forensic Bootable media☆15Updated 5 years ago
- ☆43Updated 8 years ago
- Mount, dump and analyze APFS volumes and containers☆41Updated 7 years ago
- A Kext that can be used to disable Rootless in OS X El Capitan/macOS Sierra. You need to sign it OR use an exploit to make OS X load it.☆79Updated 5 years ago
- A minimal malware analysis sandbox for macOS☆29Updated 2 years ago
- slightly modified version of jonathan levins lsdtrip bin available at http://newosxbook.com/tools/lsdtrip.html☆19Updated last year
- Parasite.kext☆36Updated 9 years ago
- A parser for Unified logging tracev3 files☆86Updated last year
- MacOS X process monitor using EndpointSecurity extension.☆35Updated 4 years ago
- Inject a DyLib to an existing Mach-O file☆23Updated 9 years ago
- Automatically exported from code.google.com/p/mac-osx-forensics☆28Updated 9 years ago
- anyKextLoader is a program that can be used to disable SIP without rebooting.☆39Updated 9 years ago
- Tools to measure an app's App Sandbox usage☆25Updated 5 years ago
- XProtect configuration files stats☆20Updated 7 years ago
- A Ghidra extension for reverse-engineering macOS binaries.☆19Updated 4 months ago
- CVE-2020–9934 POC☆23Updated 4 years ago
- A parsing tool for backgrounditems.btm☆49Updated 9 months ago
- Parse the Mac Quickook index.sqlite database☆53Updated 8 years ago
- Sniffing on port messages☆25Updated 8 years ago
- A library to parse macOS FsEvents☆19Updated 2 years ago