My latest blog post on how in memory JXA exec, dylib exec, keylogging, and other techniques look through the lens of Apple’s ESF 🔎: https://t.co/raV4jKh7lK
One thing I’m being reminded of lately: the only sure foundation that I have is Jesus Christ 🙏🏽. His kingdom transcends this economy and job market 🙌🏽.
If I can help in any way during these uncertain times please reach out! Be encouraged!
Alright here’s a new blog post for a new macOS malware by @AdamJKohler and I!
This was a fun one to reverse: stripped, encoded strings, persistence, and more :)
Enjoy!!
https://t.co/TH50w8Sptl
What have I been doing recently? Working on a 100% automated attack simulation framework for Microsoft Defender 🛡️ called M0rphy (named after Paul Morphy the chess genius) that supports both Linux, macOS and Windows, as well as accidently finding some vulns while doing so!
🆕🍎My new blogpost @KandjiMDM about how Apple attempts to mitigate some installer script vulnerabilities using "Install Script Actions" and "Install Script Mutations" in the PackageKit framework.
https://t.co/Wrx0cEfGN4
The recent macOS malware which leverages python and ObjC has some pretty cool functionality.
How it creates the path for the .py script for killing the NotificationCenter is a fun one so let's dive in:
🧵
Mythic just got an update! ✨
Check out @its_a_feature_'s latest blog post for a rundown of the updates made in Mythic v3.2, including:
✅ Push C2
✅ Interactive Async Tasking
✅ Dynamic File Browser
Read more! https://t.co/ncumn1ajnA
Dropping a quick blog post with a few videos walking through a review of how Gatekeeper looks up Notarization tickets! Calling the endpoint yourself is super quick.
https://t.co/Tcz36JWs7v
💺 SwiftBelt
A macOS enumeration tool
Stealthy: uses Swift instead of CLI tools, avoids pop-ups
Checks:
* Full disk access
* Presence of security tools
* Searches for SSH and cloud creds
* Browser history
* Slack cookies
+ more
By @cedowens#redteam
https://t.co/NeWboMXXGC
I put all my slides, whitepapers, workbooks, etc... for all of my past workshops and talks on my blog and added links for recordings where available. Now it's all available in a single space.
https://t.co/hLq264uEN6
🎉🥁 The wait is over. Please welcome "Dock Tile Plugins" to the persistence club. My new favorite. 🤩 In the blog:
🍎 background and details
🍎 how to create and use
🍎 how to detect
🍎 sample code and binary
https://t.co/91FuW4w8SZ