osx-security-awesome AwesomeTravis


A collection of OSX/iOS security related resources


News


Linking a microphone

Mac Virus

Intego Mac Security Blog

Objective-See

The Safe Mac

Mac Security

OSX Daily

Hardening

macops

SUpraudit

EFIgy

Launchd

OSX startup sequence

Google OSX hardening

Run any command in a sandbox

Sandblaster

OSX El Capitan Hardening Guide

Hardening hardware and choosing a good BIOS

Malware sample sources

Objective-See

Digital Forensics / Incident Response (DFIR)

APOLLO tool

Reverse engineering

New OS X Book

Presentations and Papers

Area41 2018: Daniel Roethlisberger: Monitoring MacOS For Malware And Intrusions

Windshift APT

Thunderstrike

Virus and exploit writeups

Detailed Analysis of macOS/iOS Vulnerability CVE-2019-6231

A fun XNU infoleak

Meltdown

Mokes

MacKeeper

OpinionSpy

Elanor

Mac Defender

Wire Lurker

KeRanger

Ian Beer, Google Project Zero: “A deep-dive into the many flavors of IPC available on OS X.”

PEGASUS iOS Kernel Vulnerability Explained

Analysis of iOS.GuiInject Adware Library

Broadpwn

Reverse Engineering and Abusing Apple Call Relay Protocol

Exploiting the Wifi Stack on Apple Devices

Google’s Project Zero series of articles that detail vulnerabilities in the wireless stack used by Apple Devices * Over The Air: Exploiting Broadcom’s Wi-Fi Stack (Part 1) * Over The Air: Exploiting Broadcom’s Wi-Fi Stack (Part 2) * Over The Air - Vol. 2, Pt. 1: Exploiting The Wi-Fi Stack on Apple Devices * Over The Air - Vol. 2, Pt. 2: Exploiting The Wi-Fi Stack on Apple Devices * Over The Air - Vol. 2, Pt. 3: Exploiting The Wi-Fi Stack on Apple Devices

ChaiOS bug

Useful tools and guides

Mac@IBM

Remote Access Toolkits

Empyre

Bella

Stitch

Pupy

EggShell surveillance tool - Works on OSX and jailbroken iOS

EvilOSX - Pure python post-exploitation toolkit

Worth following on Twitter

Other OSX Awesome lists

osxsecurity.md Github