Knockknock Logo

Knockknock

0
Free
Visit Website

KnockKnock is a free, open-source tool that uncovers persistently installed software on macOS, helping to generically reveal malware. It scans known locations where persistent software or malware may be installed, and provides detailed information about each item, including its hash, size, plist, and signed status. KnockKnock also integrates with VirusTotal to retrieve information about the files and allows users to submit unknown files for analysis. The tool provides a user-friendly interface to display the results, with options to filter out signed Apple and whitelisted items, and to save the findings as a JSON file. KnockKnock can also be run via the command line, allowing for programmatic deployment and execution. Overall, KnockKnock is a valuable tool for macOS users to detect and analyze persistently installed software and potential malware on their systems.

FEATURES

ALTERNATIVES

Sophos Intercept X Endpoint is a comprehensive endpoint security solution that provides unparalleled protection against advanced attacks, ransomware, and data loss.

A simple ransomware protection that intercepts and kills malicious processes attempting to delete shadow copies using vssadmin.exe.

A collection of scripts to harden Windows 10 security and privacy

GravityZone is a unified endpoint security and analytics platform that provides risk assessment, threat prevention, and incident response capabilities.

A laser tripwire tool to hide windows, lock computer, or execute custom scripts upon motion detection.

Advanced Endpoint Protection is a complete endpoint protection platform that provides advanced threat protection against ransomware, data breaches, and malware.

A free endpoint security tool for host investigative capabilities to find signs of malicious activity through memory and file analysis.

Open-source tool for monitoring macOS hosts with detailed system activity insights.

PINNED