7 ms·
OSXAuditor is pretty dope and we used it a bunch at Yelp. Over time, we created what we think is an inspired next version - https://github.com/Yelp/osxcollector
by c0wl 12y ago
OSXAuditor is pretty dope and we used it a bunch at Yelp. Over time, we created what we think is an inspired next version - https://github.com/Yelp/osxcollector https://github.com/Yelp/osxcollector
- deleted 12y ago[deleted]
- traveller_57681 12y agoThe passive scan approach has the single weakness that it appears to be effective, but mostly is security theatre. Take for example, when we travelling into Australia, and they asked if we had any criminal convictions - I didn't know that a conviction was still an entry requirement for the island!
- crag 12y agoI run OSXCollector and I get missing modules error. I'm not a python guy, but looking at the code, it requires: import Foundation, import calendar, import os, import sys, import shutil I assuming os, sys, and shutil are part of the system (are they?). What about the other two? Also, which version of Python do I run this under?
- ddp 12y ago...not a python user either. The README mentions 'pip' but I don't seem to have one of those either.
- texuf 12y agoHere's a "non-magical introduction to pip" http://www.dabapps.com/blog/introduction-to-pip-and-virtualenv-python/ http://www.dabapps.com/blog/introduction-to-pip-and-virtuale... Pip is an excellent package management system.
- deleted 12y ago[deleted]
- jschneier00 12y agocalendar is a builtin as well. It appears the OSX specific modules are located (on latest Mavericks) in /System/Library/Frameworks/Python.framework/Versions/2.7/Extras/lib/python So you need to add that directory (for xattr) as well as that directory + PyObjC (for Foundation) to your PYTHONPATH
- crag 12y agoStill get the error. Added PYTHONPATH to my bash_profile. After getting the error again, I looked at that location - it exists but the mods in question (Foundation and Calendar) are not there. I'm on OSX 10.9.4. It doesn't really matter enough to waste time on though. Thanks for your help. I just want to point out that in the docs "self contained" doesn't mean the user has to go hunting for mods.
- c0wl 12y agoOn a reasonably modern Mac, all the dependencies should be setup by default - including modules and the correct version of Python.
- sjy 12y agoI'm on 10.9.4 and I ran into a bunch of problems (which seem to be covered by github issues[1] already). [1] https://github.com/jipegit/OSXAuditor/issues/27 https://github.com/jipegit/OSXAuditor/issues/27
- fastball 12y agoFoundation is part of the pyobjc package. You'll need to install that.
- atmosx 12y agoIf you're on a mac using brew or macports usually the paths are usually different. Macports/Brew python doesn't usually have 'pyobjc'. Try running osxcollector as: sudo /usr/bin/python osxcollector.py
- chrissnell 12y agoWhat's up with the blurb on your GH page that says, "Exactly how Yelp uses the output from OSXCollector is a bit of our secret sauce"? How is workstation auditing a part of Yelp's secret sauce? You're a review site. Strong security on Internet-connected machines benefits everybody. There's no competitive advantage here. If you have something awesome, why not share it?
- c0wl 12y agoYeah, that could have been stated better. I guess I meant to say we're not handing out on GH the indicators of compromise for stuff that's currently giving us problems. But we do, in the README and when we talk to folks about OSXCollector, try to share how we do analysis. I'm hoping to release some related tools over the next few weeks that do some amount of parsing and analysis of the output. There's some neat stuff we've played with (though nothing short of manual analysis is giving really high confidence at this point). Some of the ideas we played with but haven't written about yet: * Feed the output through a parser that finds domains, URLs, and IPs. Feed those into threat feeds and passive DNS APIs. Occasionally this surfaces interesting stuff. * Feed all the hashes to VirusTotal, cymru, or known lists of nasty stuff. Hits are generally nasty. * We've got some known indicators of commodity malware persistence in launch agents. We grep for those cause we know they've hit us before. One of the recent things we did add to OSXCollector was pulling xattr's from downloads. This allows us to find the source URL - sometimes even the redirect chain - for a download by reading extended attributes of the file. This has been helpful.
- atmosx 12y agoHow do you read in human-friendly format the 'json' file created? Do you have any extra tool to create HTML, etc. or do I need to roll up my own json parser?