Documentation menu

Software

SeKretSauce

A macOS security toolkit: an Endpoint Security agent that watches the machine, a command line tool for investigating it, a SwiftUI dashboard, and ProtectX for firewall control.

What it is

ComponentWhat it does
sekretsaucedRoot daemon built on Apple's Endpoint Security framework. Monitors exec, fork, exit, open, write, rename, unlink, signal, kext load and mount events, correlates ransomware and malware behavior, and records incidents.
sekretsauceGo CLI for investigating a Mac: keychain, certificates, hidden processes and launch agents, app bundles, secrets, wallets, CAs and breach checks, plus browser export.
SeKretSauce.appSwiftUI dashboard for scans and agent status
ProtectXPF and Application Firewall manager with its own PF anchor and a privileged helper
ssh-wrapperOptional SSH wrapper that can record sessions in asciicast v2 format
SeKretSauce runs locally and needs no SecretServer account. The agent serves its control interface locally by default; a remote endpoint must use HTTPS and an API key set with --setup.

Who it is for

  • macOS administrators, security engineers and incident responders who can deploy a root daemon with the Endpoint Security entitlement and Full Disk Access.
  • Individual users who want to audit their own Mac with the CLI alone, without installing the agent.

Install

The repository is public under the MIT license at github.com/straticus1/SeKretSauce. There are no prebuilt releases. Install the CLI with Go 1.25.2 or newer:

go install github.com/straticus1/SeKretSauce/sekretsauce-cli/cmd/sekretsauce@latest

Or build everything from a checkout:

git clone https://github.com/straticus1/SeKretSauce.git
cd SeKretSauce
make build          # CLI: ./bin/sekretsauce
make install        # copies it to /usr/local/bin
make gui            # dashboard: gui-apps/app/build/SeKretSauce.app (needs Xcode)

Agent

swift build -c release
sudo ./scripts/install.sh
sudo "/Library/Application Support/SeKretSauce/sekretsauced" --setup   # optional: remote endpoint and API key

The agent installs as the LaunchDaemon com.sekretsauce.daemon. Set CODE_SIGN_IDENTITY when building to sign with your own identity; ad-hoc builds cannot use the agent control interface.

Use

sekretsauce scan --profile quick --json      # keychain, hidden items and apps
sekretsauce scan                             # full profile: adds secrets, wallets and CAs
sekretsauce scan certs --domain example.com  # certificate transparency
sekretsauce export chrome                    # browser export: firefox, chrome or safari
sekretsauced --status --json                 # agent status, no sudo needed
Exit codeMeaning
0Scan completed
2Scan partial or incomplete
1Any other error, such as a bad invocation

Password checks against Have I Been Pwned use the k-anonymity range API. Account lookups need --check-breaches and a HIBP_API_KEY.

Configuration and paths

SettingEffect
SEKRETSAUCE_RECORD_SSH=1Opt in to SSH session recording through ssh-wrapper. Off by default.
SEKRETSAUCE_ENABLE_TASK_RESPONSE=1Opt in to suspending suspect processes during an incident. Off by default.
HIBP_API_KEYEnables breach account lookups
/Library/Application Support/SeKretSauce/Agent install directory, with logs/ (audit) and incidents/
/Library/Logs/SeKretSauce/daemon.log and daemon-error.log
~/Library/Application Support/SeKretSauce/Per-user recordings/ and the dashboard's scan-history/ (last 20 reports)

Platform support and limits

ComponentRequirement
Agent and CLImacOS 13 or newer
Dashboard and ProtectX GUImacOS 14 or newer
AgentRoot, the Endpoint Security entitlement and Full Disk Access
  • The DNS and transparent proxy network extensions deliberately refuse to start; the passive content filter remains available.
  • Endpoint Security events are notifications, so containment cannot undo writes that already happened.
  • Logs are not encrypted by the application.
  • Cancelling a scan from the dashboard does not stop child processes it started.