macOS
macos
macOS saldırı yüzeyi uygulamalar, LaunchAgent/Daemon zincirleri, library injection, XPC ve TCC izin modelinden beslenir. Aşağıdaki başlıklar enum → bypass → yükseltme akışını izler.
Konu başlıkları
Section titled “Konu başlıkları”- macOS Auto Start
- macOS Red Teaming
- macOS Keychain
- Enrolling Devices in Other Organisations
- macOS MDM
- macOS Serial Number
- macOS Security & Privilege Escalation
- macOS Kernel & System Extensions
- macOS IOKit
- macOS Kernel Extensions & Kernelcache
- macOS Kernel Vulnerabilities
- macOS NVRAM
- macOS System Extensions
- macOS AppleFS
- Introduction to ARM64v8
- macOS Apps - Inspecting, debugging and Fuzzing
- Introduction to x64
- Objects in memory
- macOS Objective-C
- macOS Bypassing Firewalls
- macOS Defensive Apps
- Macos Dyld Hijacking And Dyld Insert Libraries
- macOS File Extension & URL scheme app handlers
- macOS Files, Folders, Binaries & Memory
- macOS Bundles
- macOS Installers Abuse
- macOS Memory Dumping
- macOS Sensitive Locations & Interesting Daemons
- macOS Universal binaries & Mach-O Format
- macOS GCD - Grand Central Dispatch
- macOS Privilege Escalation
- macOS Process Abuse
- macOS .Net Applications Injection
- macOS Automator, Preference Panes & NSServices
- macOS Chromium Injection
- macOS Dirty NIB
- macOS Electron Applications Injection
- macOS Function Hooking
- macOS IPC - Inter Process Communication
- macOS MIG - Mach Interface Generator
- macOS Thread Injection via Task port
- macOS XPC
- macOS XPC Authorization
- macOS XPC Connecting Process Check
- macOS PID Reuse
- macOS xpc_connection_get_audit_token Attack
- macOS Java Applications Injection
- macOS Library Injection
- macOS Dyld Hijacking & DYLD_INSERT_LIBRARIES
- macOS Dyld Process
- macOS Perl Applications Injection
- macOS Python Applications Injection
- macOS Quick Look Generators
- macOS Ruby Applications Injection
- macOS XPC Mach Services Abuse
- macOS Network Services & Protocols
- macOS Security Protections
- macOS - AMFI - AppleMobileFileIntegrity
- macOS Authorizations DB & Authd
- macOS Code Signing Weaknesses & Sandbox Escapes
- macOS Code Signing
- macOS Dangerous Entitlements & TCC perms
- macOS FS Tricks
- macOS xattr-acls extra stuff
- macOS Gatekeeper / Quarantine / XProtect
- macOS Input Monitoring, Screen Capture & Accessibility
- macOS Launch/Environment Constraints & Trust Cache
- macOS MACF - Mandatory Access Control Framework
- macOS Sandbox
- macOS Default Sandbox Debug
- macOS Sandbox Debug & Bypass
- macOS Office Sandbox Bypasses
- macOS Sealed System Volume & DataVault
- macOS SIP
- macOS TCC
- macOS Apple Events
- macOS TCC Bypasses
- macOS Apple Scripts
- macOS TCC Credential & Data Theft
- macOS TCC Payloads
- macOS Users & External Accounts
- macOS Useful Commands