Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
macnoise
command
MacNoise - macOS telemetry noise generator for EDR testing and security research.
|
MacNoise - macOS telemetry noise generator for EDR testing and security research. |
|
internal
|
|
|
audit
Package audit provides OCSF 1.7.0-aligned structured audit logging for MacNoise runs.
|
Package audit provides OCSF 1.7.0-aligned structured audit logging for MacNoise runs. |
|
config
Package config handles loading and validation of MacNoise configuration.
|
Package config handles loading and validation of MacNoise configuration. |
|
output
Package output handles structured telemetry event formatting and emission.
|
Package output handles structured telemetry event formatting and emission. |
|
prereqs
Package prereqs provides helpers for validating runtime prerequisites such as OS type, privilege level, and command availability.
|
Package prereqs provides helpers for validating runtime prerequisites such as OS type, privilege level, and command availability. |
|
runner
Package runner orchestrates the execution of macnoise telemetry modules.
|
Package runner orchestrates the execution of macnoise telemetry modules. |
|
modules
|
|
|
endpoint_security
Package endpointsecurity provides telemetry modules that trigger Endpoint Security framework event types.
|
Package endpointsecurity provides telemetry modules that trigger Endpoint Security framework event types. |
|
file
Package file provides telemetry modules for file system activity simulation, covering file creation and modification patterns that trigger EDR file events.
|
Package file provides telemetry modules for file system activity simulation, covering file creation and modification patterns that trigger EDR file events. |
|
network
Package network provides telemetry modules for network activity simulation, covering TCP connections, listening sockets, HTTP beaconing, DNS resolution, and reverse shell patterns used for EDR and detection engineering validation.
|
Package network provides telemetry modules for network activity simulation, covering TCP connections, listening sockets, HTTP beaconing, DNS resolution, and reverse shell patterns used for EDR and detection engineering validation. |
|
plist
Package plistmod provides telemetry modules for plist file creation and modification, generating file write events and defaults-system activity observed by EDR sensors.
|
Package plistmod provides telemetry modules for plist file creation and modification, generating file write events and defaults-system activity observed by EDR sensors. |
|
process
Package process provides telemetry modules for process activity simulation, covering process spawning, dylib injection, and signal delivery patterns used by macOS malware and targeted attack tooling.
|
Package process provides telemetry modules for process activity simulation, covering process spawning, dylib injection, and signal delivery patterns used by macOS malware and targeted attack tooling. |
|
service
Package service provides telemetry modules for LaunchAgent and LaunchDaemon persistence simulation.
|
Package service provides telemetry modules for LaunchAgent and LaunchDaemon persistence simulation. |
|
tcc
Package tcc provides telemetry modules for TCC (Transparency, Consent, and Control) permission probing.
|
Package tcc provides telemetry modules for TCC (Transparency, Consent, and Control) permission probing. |
|
xpc
Package xpc provides a telemetry module for XPC service enumeration via launchctl, generating IPC discovery activity observable by macOS security tooling.
|
Package xpc provides a telemetry module for XPC service enumeration via launchctl, generating IPC discovery activity observable by macOS security tooling. |
|
pkg
|
|
|
module
Package module defines the core Generator interface and supporting types used by all MacNoise telemetry modules.
|
Package module defines the core Generator interface and supporting types used by all MacNoise telemetry modules. |
Click to show internal directories.
Click to hide internal directories.