Pinned Repositories
EnterDebugger
A kext to facilitate calling PE_enter_debugger on machines that don't respect Cmd-Ctrl-Opt-Shift-Esc
gapstone
gapstone is a Go binding for the capstone disassembly library
mockc2
An interactive mock C2 server
osx_and_ios_kernel_programming
Updated sample code for OS X and iOS Kernel Programming book
sb
A Go library for working with macOS SBPL files
system_policy
osquery table extension that allows querying of information from the macOS private SystemPolicy.framework
USBApp
A small test app that tries to load a USBDriverKit system extension
XProtect
macOS XProtect definition files
knightsc's Repositories
knightsc/USBApp
A small test app that tries to load a USBDriverKit system extension
knightsc/gapstone
gapstone is a Go binding for the capstone disassembly library
knightsc/XProtect
macOS XProtect definition files
knightsc/osx_and_ios_kernel_programming
Updated sample code for OS X and iOS Kernel Programming book
knightsc/system_policy
osquery table extension that allows querying of information from the macOS private SystemPolicy.framework
knightsc/hopper
A collection of Hopper plugins and scripts
knightsc/EndpointSecurity
A module to expose the Endpoint Security library to Swift
knightsc/Tracer
macOS application that makes use of the EndpointSecurity framework
knightsc/darwin-xnu
The Darwin Kernel (mirror)
knightsc/CVE
A collection of CVE POC code
knightsc/CoreAnimationPlayground
A Swift playground demonstrating how to use Core Animation
knightsc/lldb
A collection of lldb scripts and configuration files
knightsc/knightsc.github.io
Content for https://knight.sc
knightsc/Presentations
Slides from various presentations and conferences
knightsc/sandbox_profiles
A collection of sandbox files from macOS 10.9 through 10.15
knightsc/r2
A collection of radare2 scripts and configuration files
knightsc/sb
A Go library for working with macOS SBPL files
knightsc/xv6-riscv
Xv6 for RISC-V
knightsc/mockc2
An interactive mock C2 server
knightsc/aws-apigateway-lambda-authorizer-blueprints
Blueprints and examples for Lambda-based custom Authorizers for use in API Gateway.
knightsc/binee
Binee: binary emulation environment
knightsc/capstone
Capstone disassembly/disassembler framework: Core (Arm, Arm64, EVM, M68K, M680X, MOS65xx, Mips, PPC, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings.
knightsc/homebrew-core
🍻 Default formulae for the missing package manager for macOS
knightsc/micromdm
Mobile Device Management server
knightsc/PasteHunter
Scanning pastebin with yara rules
knightsc/ScatterBee_Analysis
Scripts to aid analysis of files obfuscated with ScatterBee.
knightsc/scep
Go SCEP server
knightsc/tau-tools
A repo containing tools developed by Carbon Black's Threat Research Team: Threat Analysis Unit
knightsc/visualboyadvance-m
Our goal is to improve upon VisualBoyAdvance by integrating the best features from the various builds floating around. In order to uncompress the downloaded package, you need a zip extractor.
knightsc/yara
The pattern matching swiss knife