MacVM provides a comprehensive Model Context Protocol (MCP) server designed for macOS security research and malware analysis. It establishes an SSH connection to a macOS target, offering a rich toolkit of over 40 capabilities for static, behavioral, network, persistence, and dynamic analysis. With integrated composite playbooks, prompts, and resources, it streamlines the entire macOS threat triage process, delivering structured markdown reports for automated workflows like full triage, behavioral monitoring, app bundle audits, and incident response scans. It prioritizes security with fixes for shell injection, sudo password leaks, and SSH host-key trust, making it a robust platform for in-depth macOS threat investigation.
Características Principales
01Over 40 macOS-specific security and analysis tools
02Secure SSH connectivity with robust credential handling and host-key verification
03Support for static, behavioral, network, persistence, and dynamic (Frida, LLDB) analysis
040 GitHub stars
05Four composite playbooks for automated end-to-end analysis workflows
06Five contextual prompts and five dynamic resources for deeper insights