The ESF Playground

Download ESFPlayground A Note: This tool has been upgraded since it’s original creation. Read the changes here The ESF Playground Over the past few months there have been multiple times where I’ve wanted to view all of the events in which the Apple Endpoint Security Framework (ESF) has to offer Read more

MonitorUI Tool Release

Download MonitorUI MonitorUI For those that read my in depth coverage on low-level process hunting or any of my blogposts on TrueTree, you know that I’m a stickler for process hunting on macOS. For this reason, I have about a million and one different ways in which I like to Read more

Hurdling the Runningboards

Hurdling the Running boards NOTE: This research was relevant on macOS 10.16 and prior. Changes to macOS 11 have broken this approach. The blog post remains for research but true tree has been rolled back to its previous state which does not attempt to get around the runningboardd “hurdles”. Welcome Read more

The TrueTree Concept

Download TrueTree The TrueTree Concept The process tree is incredibly important when it comes to threat hunting. It doesn’t matter what platform you’re on. Every action that occurs on the operating system can be tied back to the process that caused it. Based on the combined actions that this process Read more