
Sharvil Shah
@sharvil
Security Stuff — #osquery Technical Steering Committee member, likes macOS internals | email: [email protected]
ID: 14094115
07-03-2008 09:24:57
934 Tweet
496 Followers
1,1K Following

Aloha friends. Yesterday, catastrophic fires destroyed much of Maui💔 Maui, my home, is also the birthplace of the Objective-See Foundation foundation & #OBTS conf. We're launching a fundraiser to help those who lost everything: gofundme.com/f/5auw5q-maui-… Any support much appreciated 🙏🏽

Thank you Midnight Sun! I had such a great time, it was so nice to meet old and new friends, play a few challenges and talk about macOS security tooling.

Come say hello, I am attending macsysadmin live for the first time!

Nice to see osquery getting a lot of love from Edward “☃️” Marczak at macsysadmin conference. Sometimes working on open source can feel tireless but talks like this make it all worth it!


We have some exciting news! Join Patrick Wardle Andy Rozenberg and our host christine 🌸💐🌺🌷🌹🪻🍃🌱🌿🪴✨ to talk about Objective-We on October 10th at 6:30PM CET! Check us out on YouTube.com/@herhaxpodcast live or for the replay!


Excellent talk (and epic graphics) on reversing RustBucket on macOS by Jaron Bradley and Ferdous Saljooki at #OBTS


Excellent new tool release — Kronos, to augment TCC data on macOS by Luke Roberts and Calum Hall at #OBTS


Super stoked about this talk at #OBTS! Pete Markowsky and @byaaaaahhh sharing ins and outs of the Santa agent on macOS, very cool!


After this talk by Wojciech Reguła at #OBTS I am afraid to run any Electron apps on my Mac! Excellent overview


Had so much fun working on this with Chris Long and Material Security! EndpointSecurity based File Integrity Monitoring in #osquery, particularly for file open events is a game changer for detections on macOS




This talk by Nick Frost on stopping CookieTheft on macOS (using Santa and OSQuery) youtube.com/live/ZY26xH9ni… was solid.



I’m gonna be MacDevOpsYVR, come say hello!

Starting to think I should have made #OBTS bingo cards - I don’t think I’ve ever heard a speaker use the phrase “bee’s knees” before 😹 Sharvil Shah dropping some jokes along with FSKit knowledge ❤️


Sharvil (Sharvil Shah) showed #OBTS how Apple’s new FSKit lets you build filesystems in userspace - you can build a pseudo-FS, use it as a honeypot for infostealers and even a hiding spot for malware. DM him if you need help using this as a Canary/tripwire in your environment!
