Knockknock Logo

Knockknock

0
Free
Visit Website

KnockKnock is a free, open-source tool that uncovers persistently installed software on macOS, helping to generically reveal malware. It scans known locations where persistent software or malware may be installed, and provides detailed information about each item, including its hash, size, plist, and signed status. KnockKnock also integrates with VirusTotal to retrieve information about the files and allows users to submit unknown files for analysis. The tool provides a user-friendly interface to display the results, with options to filter out signed Apple and whitelisted items, and to save the findings as a JSON file. KnockKnock can also be run via the command line, allowing for programmatic deployment and execution. Overall, KnockKnock is a valuable tool for macOS users to detect and analyze persistently installed software and potential malware on their systems.

FEATURES

ALTERNATIVES

YARA-Endpoint is a client-server architecture tool that can be used for endpoint protection and incident response.

A discontinued project for Windows system administration that has been archived due to the author's dissatisfaction with the Windows operating system.

Sophos Intercept X Endpoint is a comprehensive endpoint security solution that provides unparalleled protection against advanced attacks, ransomware, and data loss.

Xcitium's unified zero-trust platform secures endpoints to cloud workloads using patented Zero Dwell technology, providing complete protection from ransomware and malware infections.

Endpoint security solution for businesses with advanced threat protection and management

A collection of utilities for working with USB devices on Linux

Comprehensive endpoint security solution for enterprise networks and SMBs

An alternative to the auditd daemon with goals of safety, speed, JSON output, and pluggable pipelines connecting to the Linux kernel via netlink.

PINNED