{"id":22748113,"url":"https://github.com/githubfoam/macos-githubactions","last_synced_at":"2026-04-17T12:32:34.219Z","repository":{"id":49554114,"uuid":"387452075","full_name":"githubfoam/macos-githubactions","owner":"githubfoam","description":"macos osquery","archived":false,"fork":false,"pushed_at":"2022-12-06T07:54:26.000Z","size":48,"stargazers_count":0,"open_issues_count":2,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-03-30T05:42:40.498Z","etag":null,"topics":["dfir","java","macos","matrix","osquery"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/githubfoam.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-07-19T12:12:50.000Z","updated_at":"2021-12-23T10:51:55.000Z","dependencies_parsed_at":"2023-01-23T18:16:08.817Z","dependency_job_id":null,"html_url":"https://github.com/githubfoam/macos-githubactions","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/githubfoam/macos-githubactions","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/githubfoam%2Fmacos-githubactions","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/githubfoam%2Fmacos-githubactions/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/githubfoam%2Fmacos-githubactions/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/githubfoam%2Fmacos-githubactions/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/githubfoam","download_url":"https://codeload.github.com/githubfoam/macos-githubactions/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/githubfoam%2Fmacos-githubactions/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31929614,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-17T10:35:34.458Z","status":"ssl_error","status_checked_at":"2026-04-17T10:35:09.472Z","response_time":62,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["dfir","java","macos","matrix","osquery"],"created_at":"2024-12-11T03:19:43.012Z","updated_at":"2026-04-17T12:32:34.201Z","avatar_url":"https://github.com/githubfoam.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# macos-githubactions\n\n[![.github/workflows/macos-osquery-workflow.yml](https://github.com/githubfoam/macos-githubactions/actions/workflows/macos-osquery-workflow.yml/badge.svg?branch=main)](https://github.com/githubfoam/macos-githubactions/actions/workflows/macos-osquery-workflow.yml)  \n[![matrix java macos CI workflow](https://github.com/githubfoam/macos-githubactions/actions/workflows/jdk-matrix-wf.yml/badge.svg)](https://github.com/githubfoam/macos-githubactions/actions/workflows/jdk-matrix-wf.yml)\n\nCTI, DFIR, OSX\n~~~~\nFinding specific indicators of compromise (IOCs) in memory or on disk; Facebook has provided the queries which detect Hacking Team’s OSX backdoor by querying for specific persistent mechanisms and file system activity on OSX\n\nselect * from file where path = '/dev/ptmx0';\nselect * from apps where bundle_identifier = 'com.ht.RCSMac' or bundle_identifier like 'com.yourcompany.%' or bundle_package_type like 'OSAX';\nselect * from launchd where label = 'com.ht.RCSMac' or label like 'com.yourcompany.%' or name = 'com.apple.loginStoreagent.plist' or name = 'com.apple.mdworker.plist' or name = 'com.apple.UIServerLogin.plist';\n\n\n~~~~\n~~~~\nmacos_osquery \nhttps://gist.github.com/githubfoam/6753b5efad8e5ab8fa2ca29ce7b29988\nwindows_osquery \nhttps://gist.github.com/githubfoam/afeb4fbbee731c427d645382e59b7948\nlinux_osquery \nhttps://gist.github.com/githubfoam/0babb95da5845b8d4ee41f5711de637a\n~~~~\n\n~~~~\npredefined tables\n\u003chttps://osquery.io/schema/4.1.1\u003e\n\n# https://osquery.readthedocs.io/en/stable/installation/install-linux/\n\nhttps://github.com/google/santa\nhttps://github.com/groob/moroz\nhttps://github.com/zentralopensource/zentral\n\n~~~~\n\n~~~~\nhttps://github.com/actions/runner-images\n~~~~","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgithubfoam%2Fmacos-githubactions","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgithubfoam%2Fmacos-githubactions","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgithubfoam%2Fmacos-githubactions/lists"}