Santa is a binary and file access authorization system for macOS. It consists of a system extension that monitors for executions, a daemon that makes execution decisions based on the contents of a local database, a GUI agent that notifies the user in case of a block decision, and a command-line utility for managing the system and synchronizing the database with a server. It is named Santa because it keeps track of binaries that are naughty or nice. Docs: The Santa docs are stored in the Docs directory and are published at https://santa.dev. The docs include deployment options, details on how parts of Santa work, and instructions for developing Santa itself. Get Help: If you have questions or otherwise need help getting started, the santa-dev group is a great place. If you believe you have a bug, feel free to report an issue, and we'll respond as soon as we can. If you believe you've found a vulnerability, please read the security policy for disclosure reporting.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
All-in-one protection solution for individuals and families, offering antivirus, VPN, identity, and privacy protection.
Cortex XDR is a comprehensive endpoint security solution that blocks advanced attacks with behavioral threat protection, AI, and cloud-based analysis, and provides complete endpoint security and lightning-fast investigation and response.
GravityZone is a unified endpoint security and analytics platform that provides risk assessment, threat prevention, and incident response capabilities.
Kunai is a Linux-based system monitoring tool that provides real-time monitoring and threat hunting capabilities.
Automated and flexible approach for deploying Windows 10 with security standards set by the DoD.
Avira Free Security is an all-in-one security, privacy, and performance app for Mac, providing real-time protection, password management, VPN, and more, all for free.
An endpoint monitoring tool for Linux and macOS that reports file, socket, and process events to Zeek.
Emsisoft Enterprise Security + EDR provides robust and proven endpoint security for organizations of all sizes with layered protection and a cloud-based management console.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.