This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Objective-See | |
|---|---|
| Name | Objective-See |
| Developer | Theodore "Patrick" Wardle |
| Released | 2010s |
| Programming language | Objective-C, C, Swift, Assembly |
| Operating system | macOS |
| Genre | Security software, malware analysis, forensics |
| License | Various (open source, freeware) |
Objective-See Objective-See is a collection of macOS security tools and research projects created and maintained by Theodore "Patrick" Wardle. It focuses on malware detection, forensics, intrusion prevention, and threat research for Apple macOS Big Sur, macOS Catalina, macOS Monterey, macOS Ventura, macOS Sonoma and earlier versions including macOS High Sierra. The projects have been cited in reporting by outlets such as Wired (magazine), The New York Times, BBC News, and discussed at conferences including Black Hat, DEF CON, RSA Conference and USENIX.
Objective-See began as individual utilities developed by Theodore Wardle while he worked at organizations such as Synack, NASA, and the National Security Agency. Early tools emerged during the era of OS X Mavericks and OS X Yosemite as macOS became a higher-profile target following incidents involving Flashback (malware), Xagent, and XcodeGhost. Wardle presented findings at venues like Black Hat USA and DEF CON, and collaborated with researchers from Google Project Zero, Microsoft Research, Kaspersky Lab, ESET, and CrowdStrike. The project evolved alongside macOS security developments from System Integrity Protection to Apple T2 Security Chip and the transition to Apple silicon.
Objective-See comprises a suite of tools addressing different stages of incident response and threat hunting. Prominent utilities include system monitors and scanners that analyze kernel and user-space behavior, interacting with technologies such as XNU (kernel), Launch Services, Kernel Extension (kext), and System Extensions. The toolkit intersects with forensic frameworks like Volatility (software), The Sleuth Kit, and incident platforms such as MISP and ELK Stack. Objective-See tools have been used alongside endpoint solutions from SentinelOne, Carbon Black, CrowdStrike Falcon, Sophos, ESET and network analysis tools by Wireshark, Zeek and Suricata.
Notable Objective-See releases include utilities that have become staples among macOS responders and analysts. These releases align with research into adversary techniques documented by groups such as APT28, APT29, Lazarus Group, Equation Group and OilRig. Tools have been highlighted in advisories from US-CERT, CISA, and vendors including Apple Inc., Microsoft, Google, Mozilla, and Adobe Systems. The distribution model and announcements have appeared on platforms like GitHub, Twitter, GitLab, and presented at conferences like SANS Institute and CanSecWest.
Objective-See employs low-level instrumentation and behavioral analysis, leveraging APIs and subsystems such as IOKit, CoreFoundation, XPC, Grand Central Dispatch, and Mach messaging. The codebase integrates language features from Objective-C, Swift (programming language), and inline Assembly language for processor-specific operations on x86-64 and ARM64 architectures. Analysis techniques reference academic work from Stanford University, MIT, Carnegie Mellon University, and Georgia Institute of Technology as well as toolchains like Clang, LLVM, GCC, and debuggers including LLDB and GDB.
Objective-See has been praised by security practitioners at companies such as Apple Inc., Google, Facebook (Meta Platforms), Amazon Web Services, Microsoft Corporation, Oracle Corporation, Intel Corporation, and AMD for practical tooling and research contributions. Coverage in media outlets including The Washington Post, Vox (website), Forbes, The Guardian, Bloomberg L.P., TechCrunch, and Ars Technica emphasized its role in uncovering macOS threats like Silver Sparrow, Shlayer, and OSX/Mokes. Academic citations reference Objective-See work in conferences like IEEE Symposium on Security and Privacy, ACM CCS, and USENIX Security Symposium.
Objective-See operates in a context shaped by laws and standards such as Computer Fraud and Abuse Act, General Data Protection Regulation, Digital Millennium Copyright Act, and disclosure frameworks like Coordinated Vulnerability Disclosure and Bug Bounty. Ethical considerations intersect with policies from institutions such as Electronic Frontier Foundation, Center for Internet Security, Open Web Application Security Project, and IETF. Discussions around reverse engineering and malware analysis involve stakeholders including law enforcement, FBI, Department of Justice (United States), and international agencies like Europol and INTERPOL.
Category:MacOS security tools