Analyzing Macos Binaries

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure. Use when analyzing a .app bundle or Mach-O on macOS, checking entitlements and notarization, hunting a dylib-hijack or XPC privilege bug, or reasoning about Gatekeeper and quarantine.

trilwu c874f00 6.6 KB Updated

File contents

trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries commit c874f00bb3

Frequently asked questions

npx skillmds add trilwu/analyzing-macos-binaries