The ESF Playground

Download ESFPlayground A Note: This tool has been upgraded since it’s original creation. Read the changes here The ESF Playground Over the past few months there have been multiple times where I’ve wanted to view all of the events in which the Apple Endpoint Security Framework (ESF) has to offer Read more…

The TrueTree Concept

Download TrueTree The TrueTree Concept The process tree is incredibly important when it comes to threat hunting. It doesn’t matter what platform you’re on. Every action that occurs on the operating system can be tied back to the process that caused it. Based on the combined actions that this process Read more…