A binary authorization and monitoring system for macOS
-
Updated
Dec 10, 2024 - Objective-C++
A binary authorization and monitoring system for macOS
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
Digging Deeper....
Tinfoil Chat - Onion-routed, endpoint secure messaging system
Red Canary Mac Monitor is an advanced, stand-alone system monitoring tool tailor-made for macOS security research. Beginning with Endpoint Security (ES), it collects and enriches system events, displaying them graphically, with an expansive feature set designed to reduce noise.
Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.
Awesome list of keywords and artifacts for Threat Hunting sessions
A desktop application that checks security-related settings and makes recommendations for improvements without requiring central device management or automated reporting.
Fast and efficient osquery management
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
Automatically audit your Mac for basic security hygiene.
iDefender(冰盾 - 终端主动防御系统)
monitor macOS for malicious activity
Endpoint detection & Malware analysis software
Authorization extension for popular web-frameworks to protect your endpoints
Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.
A binary authorization and monitoring system for macOS
Collection of tool you need to have in your Endpoint Detection and Response arsenal
Windows Exploit Protection Settings (Ultimate)
Add a description, image, and links to the endpoint-security topic page so that developers can more easily learn about it.
To associate your repository with the endpoint-security topic, visit your repo's landing page and select "manage topics."