Sorescu Andrei's starred repositories
MacRootKit
macOS RootKit that can fuzz binaries/drivers, do kernel r/w, hook kernel and userspace functions, set custom breakpoints, GDB stub (in progress), match KDK kernels with DWARF debug symbols to release kernels, MachOs of all kinds, dyld shared caches, Objective C/Swift metadata, dump libraries, library injection (e.g. cycript), and crawl iOS apps
EDR-Preloader
An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
svc-bin-acl
svc-bin-acl is a PowerShell script that enumerates Windows service binary ACLs for the purpose of identifying weak service binary permissions.