Enumerates persistently installed software on macOS, similar to AutoRuns for Windows.
KnockKnock is a macOS security tool that enumerates all persistently installed software on a system, similar to how AutoRuns works on Windows. It scans various persistence mechanisms like launch agents, login items, and browser extensions to help identify potentially unwanted programs or malware. The tool provides detailed information about each item including file paths, signing status, and threat intelligence integration.
Security professionals, system administrators, and advanced macOS users who need to audit their systems for persistent software, malware, or unwanted applications.
Developers choose KnockKnock because it provides comprehensive macOS persistence enumeration that's specifically designed for Apple's ecosystem, integrates with threat intelligence services, and offers both GUI and CLI interfaces for flexibility in different security workflows.
Like AutoRuns ...but for macOS!
Scans multiple macOS persistence mechanisms including launch agents, login items, browser extensions, and kernel extensions, providing a complete view of autostart software as highlighted in the Key Features.
Leverages VirusTotal and other sources to flag known malicious software, enhancing detection capabilities for security audits.
Offers both a graphical user interface for ease of use and a command-line interface for scripting and automation in different security workflows, as noted in the Key Features.
Allows exporting scan data in JSON format, facilitating further analysis, reporting, or integration with other tools for detailed security assessments.
KnockKnock only enumerates persistent software; it does not provide tools to remove or quarantine detected threats, requiring manual intervention for cleanup.
Malware detection relies on VirusTotal, which may require an API key and internet connection, and could introduce privacy concerns or limitations in offline environments.
The tool is specifically designed for macOS, making it unsuitable for auditing persistent software on other operating systems like Windows or Linux.
KnockKnock is an open-source alternative to the following products:
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.