Santa is a binary authorization system for macOS, aptly named since its main purpose is to keep track of binaries that are either naughty or nice. Santa is made up of a kernel extension (or a system extension on macOS 10.15+) that monitors and participates in execve() decisions, a userland daemon that makes the execution decisions, a GUI agent that shows notifications when an execve() is blocked, and a command-line utility that oversees system management and the synchronization of database and server.

Santa is built to help protect users by stopping the spread of malware and analyzing what's running on a computer, but is by no means a total security system. Ideally Santa works as a part of a defense-in-depth strategy, and other measures should be in place to protect hosts.

Features

  • Multiple modes for different cases
  • Event logging
  • Certificate-based rules, with override levels
  • Path-based rules (via NSRegularExpression/ICU)
  • Failsafe certificate rules
  • In-kernel caching
  • Userland components validate each other
  • Kernel extension uses only provided KPIs

Project Samples

Project Activity

See All Activity >

Categories

Anti-Malware

License

Apache License V2.0

Follow Santa

Santa Web Site

You Might Also Like
Gen AI apps are built with MongoDB Atlas Icon
Gen AI apps are built with MongoDB Atlas

The database for AI-powered applications.

MongoDB Atlas is the developer-friendly database used to build, scale, and run gen AI and LLM-powered apps—without needing a separate vector database. Atlas offers built-in vector search, global availability across 115+ regions, and flexible document modeling. Start building AI apps faster, all in one place.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Santa!

Additional Project Details

Operating Systems

Mac

Programming Language

Objective C

Related Categories

Objective C Anti-Malware Software

Registered

2020-11-05