Skip to content
View mattreduce's full-sized avatar
β˜•
β˜•

Organizations

@hashivim @MythicAgents @srcmtd

Block or report mattreduce

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

🍎 macos

macOS apps and security tools
150 repositories

Some random shellcodes I created

Assembly 8 4 Updated Sep 19, 2015

Swift code to programmatically perform dylib injection

Swift 52 8 Updated Oct 29, 2022

macOS Offensive Tools

Objective-C 270 32 Updated Sep 28, 2023

JXA and swift code that can perform some macOS situational awareness without generating TCC prompts.

Swift 40 2 Updated Apr 20, 2022

Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binaries with problematic/interesting entitlements. Also checks f…

Swift 98 10 Updated Sep 14, 2022

JXA implementation of some SwiftBelt functions. Author: Cedric Owens

JavaScript 46 6 Updated Jun 22, 2023

Spins up a docker container with several useful tools for offensive security in macOS/cloud environments. Also installs the needed dependencies for each tool/utility during docker setup.

Dockerfile 18 1 Updated Nov 3, 2021

Collection of Slides From My Conference Talks

20 3 Updated Nov 21, 2022

JXA Scripts for extracting data from Firefox

JavaScript 8 2 Updated Jul 29, 2021

A macOS enumeration tool inspired by harmjoy's Windows-based Seatbelt enumeration tool. Author: Cedric Owens

Swift 341 33 Updated Apr 28, 2022

A JXA script that leverages sqlite3 API calls to add items to the user's TCC database at: ~/Library/Application Support/com.apple.TCC/TCC.db

JavaScript 10 2 Updated May 21, 2021

Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.

Swift 109 8 Updated Oct 29, 2022

Swift code to programmatically execute local or hosted JXA payloads from Terminal without using the on-disk osascript binary.

Swift 23 4 Updated Apr 22, 2021

A Swift port of some of the original PersistentJXA projects by D00MFist. Original PersistentJXA repo: https://github.com/D00MFist/PersistentJXA

Swift 34 4 Updated Apr 15, 2021

Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens

Python 48 9 Updated Apr 15, 2021

A wrapper around the on disk jamf binary (for JAMF managed macOS hosts). Useful for unit testing detections of offensive jamf host-based commands.

Swift 4 1 Updated Feb 26, 2021

JXA script based on research by Jeff Johnson on leveraging TextEdit to remove quarantine attributes on files. Jeff's original research is here: https://lapcatsoftware.com/articles/sandbox-escape.html

JavaScript 17 1 Updated Jan 31, 2021

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

Swift 124 25 Updated Dec 27, 2020

Swift code to parse the quarantine history database, Chrome history database, Safari history database, and Firefox history database on macOS.

Swift 15 3 Updated Dec 3, 2020

A Swift (and slightly modified) version of Thomas Reed's PICT (Post Infection Collection Toolkit)

Swift 8 1 Updated Nov 13, 2019

Proxy Unix applications in the terminal

Go 116 12 Updated Apr 14, 2021

Developer machine management for Linux/OSX. Think Terraform/Ansible for your dotfiles/packages! βš™οΈπŸ 

Go 20 1 Updated May 11, 2023

This is a malware analyzer for Mac OS X that extends the Cuckoo Sandbox project (https://cuckoosandbox.org/)

Python 23 6 Updated Jul 8, 2016

Container runtimes on macOS (and Linux) with minimal setup

Go 27,371 545 Updated Mar 5, 2026

macOS command line tool to return the available disk space on APFS volumes

Swift 171 8 Updated Jul 28, 2025

Python module intended to assist IT administrators with manipulation of the macOS Dock.

Python 118 17 Updated Jan 20, 2026

A command-line tool and Xcode Extension for formatting Swift code

Swift 8,723 678 Updated Mar 5, 2026

Network logger for Apple platforms

Swift 6,924 356 Updated Sep 8, 2025

Swift 5 macOS agent

Swift 113 19 Updated Jul 23, 2024

A OS X crypto ransomware PoC

C 89 29 Updated Sep 4, 2015