Software
SeKretSauce
A macOS security toolkit: an Endpoint Security agent that watches the machine, a command line tool for investigating it, a SwiftUI dashboard, and ProtectX for firewall control.
What it is
| Component | What it does |
|---|---|
sekretsauced | Root daemon built on Apple's Endpoint Security framework. Monitors exec, fork, exit, open, write, rename, unlink, signal, kext load and mount events, correlates ransomware and malware behavior, and records incidents. |
sekretsauce | Go CLI for investigating a Mac: keychain, certificates, hidden processes and launch agents, app bundles, secrets, wallets, CAs and breach checks, plus browser export. |
| SeKretSauce.app | SwiftUI dashboard for scans and agent status |
| ProtectX | PF and Application Firewall manager with its own PF anchor and a privileged helper |
ssh-wrapper | Optional SSH wrapper that can record sessions in asciicast v2 format |
SeKretSauce runs locally and needs no SecretServer account. The agent serves its control interface locally by default; a remote endpoint must use HTTPS and an API key set with
--setup.Who it is for
- macOS administrators, security engineers and incident responders who can deploy a root daemon with the Endpoint Security entitlement and Full Disk Access.
- Individual users who want to audit their own Mac with the CLI alone, without installing the agent.
Install
The repository is public under the MIT license at github.com/straticus1/SeKretSauce. There are no prebuilt releases. Install the CLI with Go 1.25.2 or newer:
go install github.com/straticus1/SeKretSauce/sekretsauce-cli/cmd/sekretsauce@latest
Or build everything from a checkout:
git clone https://github.com/straticus1/SeKretSauce.git cd SeKretSauce make build # CLI: ./bin/sekretsauce make install # copies it to /usr/local/bin make gui # dashboard: gui-apps/app/build/SeKretSauce.app (needs Xcode)
Agent
swift build -c release sudo ./scripts/install.sh sudo "/Library/Application Support/SeKretSauce/sekretsauced" --setup # optional: remote endpoint and API key
The agent installs as the LaunchDaemon com.sekretsauce.daemon. Set CODE_SIGN_IDENTITY when building to sign with your own identity; ad-hoc builds cannot use the agent control interface.
Use
sekretsauce scan --profile quick --json # keychain, hidden items and apps sekretsauce scan # full profile: adds secrets, wallets and CAs sekretsauce scan certs --domain example.com # certificate transparency sekretsauce export chrome # browser export: firefox, chrome or safari sekretsauced --status --json # agent status, no sudo needed
| Exit code | Meaning |
|---|---|
| 0 | Scan completed |
| 2 | Scan partial or incomplete |
| 1 | Any other error, such as a bad invocation |
Password checks against Have I Been Pwned use the k-anonymity range API. Account lookups need --check-breaches and a HIBP_API_KEY.
Configuration and paths
| Setting | Effect |
|---|---|
SEKRETSAUCE_RECORD_SSH=1 | Opt in to SSH session recording through ssh-wrapper. Off by default. |
SEKRETSAUCE_ENABLE_TASK_RESPONSE=1 | Opt in to suspending suspect processes during an incident. Off by default. |
HIBP_API_KEY | Enables breach account lookups |
/Library/Application Support/SeKretSauce/ | Agent install directory, with logs/ (audit) and incidents/ |
/Library/Logs/SeKretSauce/ | daemon.log and daemon-error.log |
~/Library/Application Support/SeKretSauce/ | Per-user recordings/ and the dashboard's scan-history/ (last 20 reports) |
Platform support and limits
| Component | Requirement |
|---|---|
| Agent and CLI | macOS 13 or newer |
| Dashboard and ProtectX GUI | macOS 14 or newer |
| Agent | Root, the Endpoint Security entitlement and Full Disk Access |
- The DNS and transparent proxy network extensions deliberately refuse to start; the passive content filter remains available.
- Endpoint Security events are notifications, so containment cannot undo writes that already happened.
- Logs are not encrypted by the application.
- Cancelling a scan from the dashboard does not stop child processes it started.