awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
drduh avatar

drduh/macOS-Security-and-Privacy-Guide

0
View on GitHub↗
22,449 estrellas·1,462 forks·MIT·7 vistasdrduh.github.io/macOS-Security-and-Privacy-Guide↗

MacOS Security And Privacy Guide

This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set of instructions for configuring system settings to improve privacy, reduce the attack surface, and implement a malware defense framework.

The guide covers technical methods for validating software notarization, verifying application sandboxing, and auditing system activity. It distinguishes itself by providing detailed workflows for restricting high-risk features and applying advanced security configurations to protect the operating system.

The documentation covers several key capability areas, including network privacy through encrypted DNS and packet filtering, data encryption for disks and backups, and identity protection via metadata removal and anonymized browsing. It also includes procedures for system auditing by monitoring process execution and network activity.

Features

  • macOS Security Hardening - Provides a comprehensive set of curated configurations to improve the security and privacy posture of macOS.
  • System Hardening - Delivers a comprehensive guide to reducing the macOS attack surface through advanced security configurations.
  • Privacy Hardening Profiles - Provides a detailed manual for implementing privacy-focused DNS, firewall rules, and metadata removal.
  • Security Hardening Profiles - Provides comprehensive instructions for configuring macOS settings to reduce the system attack surface.
  • Security Profiles - Provides instructions for applying security-specific configuration profiles to enforce a consistent system security posture.
  • System Auditing - A technical manual for monitoring process execution and network activity using native macOS security frameworks.
  • Administrative Privilege Management - Implements a security boundary by separating daily user tasks from administrator accounts.
  • Sandbox and Isolation - Provides workflows for verifying and enforcing sandbox-based application isolation to restrict system resource access.
  • Attack Surface Analysis - Provides methods to disable specific operating system features to minimize the available attack surface.
  • Data Encryption - Protects data at rest through system-wide encryption and restricted startup disk authentication.
  • DNS Security - Provides detailed instructions for implementing encrypted DNS protocols like DoH and DoT to enhance network privacy.
  • Full Disk Encryption - Configures disk encryption to require passwords for drive access and prevent unauthorized booting.
  • Network Privacy Configurations - Secures internet traffic using a combination of encrypted DNS, firewalls, and packet filtering.
  • Digital Footprint Reduction - Offers workflows for anonymizing web browsing and clearing system metadata to protect user identity.
  • Privilege Isolation - Establishes a security boundary by isolating daily user tasks from administrative accounts.
  • Software Notarization Validators - Implements system-level gatekeeping by validating application notarization and hardened runtime signatures.
  • Activity Monitors - Implements system auditing to monitor process execution and network activity.
  • System Auditing Utilities - Provides a technical framework for monitoring process execution and network activity to detect malicious behavior.
  • Audit Logging Systems - Utilizes security modules to capture and analyze historical records of system events and process activity.
  • Dynamic System Tracing - Employs dynamic system tracing to monitor disk I/O and process execution for behavior analysis.
  • IOC and Malware Scanning - Instructs on using background signatures and third-party services to detect and remove malicious software.
  • Domain Traffic Filters - Instructs on redirecting unwanted domains to a local loopback address via the hosts file to prevent connections.
  • Inbound Connection Managers - Configures firewalls to block unauthorized inbound network connections with optional stealth mode.
  • Integrity Protection Managers - Provides procedures to check the status of kernel-level protection preventing unauthorized modifications to system files.
  • Runtime Integrity Validation - Provides technical methods to verify if software operates within a sandbox or hardened runtime.
  • Sandbox Verification - Provides workflows to check if a running program is restricted by a sandbox to limit system access.
  • Cryptographic Key Management - Covers the generation and secure storage of encryption keys using hardware tokens.
  • System Artifact Clearing - Provides methods to clear sensitive historical artifacts and metadata from system preferences and caches.
  • Encrypted Backups - Describes a redundant 3-2-1 backup model utilizing encrypted local and remote copies.
  • Encrypted DNS Resolvers - Guides the configuration of encrypted DNS, DNSSEC, and domain filtering for network privacy.
  • Software Notarization Validation - Implements a system-level gatekeeping mechanism to prevent non-notarized applications from running.
  • Hardened Runtime Verification - Provides methods to verify if a program uses a hardened runtime to prevent unauthorized code injection.
  • Hardware-Backed Security - Explains how to secure cryptographic keys and passkeys using dedicated physical hardware tokens.
  • Malware Defense Frameworks - Implements a framework for validating software notarization and verifying application sandboxing to prevent malware.
  • Packet Filtering Engines - Details the use of kernel-level packet filtering to block specific IP addresses and ranges.
  • Credential Management Tools - Provides instructions for generating strong passwords and managing hardware-based passkeys.
  • Traffic Filtering - Implements rules to block incoming and outgoing network connections using firewalls or packet filters.
  • Packet Inspection - Details how to inspect network packets to monitor DNS queries, HTTP requests, and certificates.
  • Network Traffic Monitors - Provides methods to track and block network connections using application-layer firewalls.
  • Layered Traffic Monitors - Implements a layered monitoring approach using application-layer firewalls and local proxy interception.
  • System Administration - Hardening guide for macOS security and privacy.
  • Security Guides and Resources - Detailed guide for hardening macOS security and privacy settings.
  • Curated Lists - Listed in the “Curated Lists” section of the The Book Of Secret Knowledge awesome list.
  • Seguridad y privacidad - Comprehensive guide for hardening macOS systems and privacy settings.
  • System Hardening - Comprehensive hardening guide for Apple desktop environments.

Historial de estrellas

Gráfico del historial de estrellas de drduh/macos-security-and-privacy-guideGráfico del historial de estrellas de drduh/macos-security-and-privacy-guide

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a MacOS Security And Privacy Guide

Proyectos open-source similares, clasificados según cuántas características comparten con MacOS Security And Privacy Guide.
  • drduh/os-x-security-and-privacy-guideAvatar de drduh

    drduh/OS-X-Security-and-Privacy-Guide

    22,444Ver en GitHub↗

    This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of instructions and checklists for reducing the system attack surface through manual configuration, policy enforcement, and a layered defense strategy. The guide emphasizes a system auditing framework, using binary analysis, system logs, and packet inspection to verify that security controls and application sandboxing are functioning as intended. It offers tool-agnostic recommendations, defining security goals while allowing users to select their own third-party software for implementa

    Ver en GitHub↗22,444
  • kanidm/kanidmAvatar de kanidm

    kanidm/kanidm

    4,595Ver en GitHub↗

    Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory services across distributed infrastructure. It provides a comprehensive framework for managing human and service accounts, utilizing a schema-driven database to store identity records, group memberships, and system attributes. The platform supports a wide range of authentication methods, including passkeys, passwords, and standard protocols like OAuth2, OIDC, LDAP, and RADIUS. The system distinguishes itself through a granular access control engine that enforces security policies

    Rustauthenticationiamidentity
    Ver en GitHub↗4,595
  • aws/aws-cdkAvatar de aws

    aws/aws-cdk

    12,817Ver en GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    Ver en GitHub↗12,817
  • veeral-patel/how-to-secure-anythingAvatar de veeral-patel

    veeral-patel/how-to-secure-anything

    10,224Ver en GitHub↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    secure-designsecure-systemssecurity
    Ver en GitHub↗10,224
Ver las 30 alternativas a MacOS Security And Privacy Guide→

Preguntas frecuentes

¿Qué hace drduh/macos-security-and-privacy-guide?

This project is a security hardening guide and privacy configuration manual for macOS. It provides a comprehensive set of instructions for configuring system settings to improve privacy, reduce the attack surface, and implement a malware defense framework.

¿Cuáles son las características principales de drduh/macos-security-and-privacy-guide?

Las características principales de drduh/macos-security-and-privacy-guide son: macOS Security Hardening, System Hardening, Privacy Hardening Profiles, Security Hardening Profiles, Security Profiles, System Auditing, Administrative Privilege Management, Sandbox and Isolation.

¿Qué alternativas de código abierto existen para drduh/macos-security-and-privacy-guide?

Las alternativas de código abierto para drduh/macos-security-and-privacy-guide incluyen: drduh/os-x-security-and-privacy-guide — This project is a comprehensive security hardening and privacy management guide for macOS. It provides a set of… kanidm/kanidm — Kanidm is a centralized identity management server designed to handle authentication, authorization, and directory… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… veeral-patel/how-to-secure-anything — This project is a comprehensive security suite and knowledge base focused on the engineering and construction of… lissy93/awesome-privacy — This project is a curated directory and catalog of privacy-respecting software and security-focused services. It… siderolabs/talos — Talos is a minimal, immutable Linux distribution designed specifically for deploying and managing Kubernetes clusters.…