AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
Crawler Summary
Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- name: macos-detect-and-respond description: Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- macOS Detect and Respond Purpose This skill provides specialized knowledge and workflows for macOS detection engineering. It Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.
Freshness
Last checked 4/15/2026
Best For
macos-detect-and-respond is best for cause workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- name: macos-detect-and-respond description: Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- macOS Detect and Respond Purpose This skill provides specialized knowledge and workflows for macOS detection engineering. It
Public facts
4
Change events
1
Artifacts
0
Freshness
Apr 15, 2026
Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Apr 15, 2026
Vendor
Null Event
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.
Setup snapshot
git clone https://github.com/null-event/macos-detect-and-respond-skills.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Null Event
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
Parameters
spl
index=macos sourcetype="esf:json" event_type="ES_EVENT_TYPE_NOTIFY_EXEC"
| where isnull('process.signing_id') OR 'process.signing_id'=""
| where match('process.executable.path', "^/tmp/")
| table _time, host, user, process.executable.path, process.cmdline, process.parent.nametext
Suspicious indicators: - Unsigned or ad-hoc signed - Execution from /tmp, /var/tmp, ~/Downloads - Unusual parent-child relationship - Suspicious command-line arguments (curl | bash, base64, etc.) - Network activity immediately after execution
text
Key indicators: - Launch agent/daemon creation (BTM events) - Plist modifications in LaunchAgents/LaunchDaemons - Shell profile modifications (.bashrc, .zshrc) - Login items additions - Unusual RunAtLoad + KeepAlive combinations
text
Monitor: - SUDO/SU events (userspace) - SETUID/SETGID events (kernel - more reliable) - SUID binary creation - TCC database modifications - Authorization Service abuse
text
Critical detections: - Quarantine attribute removal (com.apple.quarantine) - Code signature invalidation (CS_INVALIDATED) - Process injection (REMOTE_THREAD_CREATE, GET_TASK) - File deletion (UNLINK for logs, security files)
text
High-value detections: - Keychain file access (.keychain, .keychain-db) - Browser credential file access (Login Data, Cookies) - Memory access to security daemons (GET_TASK on securityd) - Security command execution (dump-keychain)
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- name: macos-detect-and-respond description: Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts. --- macOS Detect and Respond Purpose This skill provides specialized knowledge and workflows for macOS detection engineering. It
This skill provides specialized knowledge and workflows for macOS detection engineering. It helps translate adversary behaviors into actionable detections, understand macOS telemetry sources, write queries for multiple platforms, and triage security alerts on macOS systems.
Use this skill when:
Example queries that trigger this skill:
Translate adversary behaviors into queries, rules, or signatures for various tooling:
Supported Platforms:
Workflow:
Understand what macOS actually logs and how to access it:
Primary Sources:
For each source, understand:
Map current detections against ATT&CK for macOS:
Process:
Use the ATT&CK reference (references/attack-macos.md) to:
Determine if observed behavior is expected on macOS:
Triage Framework:
Common Alert Types:
Understand normal macOS system behavior:
Key Baselines:
Anomaly Indicators:
When writing a detection:
Start with the behavior:
Identify telemetry sources:
references/macos-telemetry-sources.mdMap to ATT&CK:
references/attack-macos.mdConsult platform-specific guidance:
references/splunk-detection-patterns.mdreferences/sigma-macos.mdreferences/osquery-tables.mdreferences/endpoint-security-framework.mdWrite the detection:
Test and iterate:
User Request: "Write a Splunk query to detect unsigned binaries executing from /tmp"
Process:
references/splunk-detection-patterns.mdindex=macos sourcetype="esf:json" event_type="ES_EVENT_TYPE_NOTIFY_EXEC"
| where isnull('process.signing_id') OR 'process.signing_id'=""
| where match('process.executable.path', "^/tmp/")
| table _time, host, user, process.executable.path, process.cmdline, process.parent.name
User Request: "Help me triage this Endpoint Security alert for suspicious launch agent creation"
Process:
Consult triage guidance: references/triage-guidance.md → Launch Agent section
Key questions:
Benign indicators:
Suspicious indicators:
Provide verdict and next steps
When a query mentions an ES event type (e.g., "What events show file modification?"):
references/endpoint-security-framework.mdAll reference materials are located in the references/ directory:
endpoint-security-framework.md
attack-macos.md
macos-telemetry-sources.md
osquery-tables.md
splunk-detection-patterns.md
sigma-macos.md
triage-guidance.md
The scripts/ directory contains practical tools that automate common detection engineering and triage tasks:
triage-process.sh - Comprehensive process investigation
./scripts/triage-process.sh 1234check-code-signature.sh - Binary trust evaluation
./scripts/check-code-signature.sh /tmp/suspicious_binaryanalyze-launch-agent.sh - Persistence mechanism analysis
./scripts/analyze-launch-agent.sh ~/Library/LaunchAgents/suspicious.plistcollect-es-events.sh - Endpoint Security event collection
./scripts/collect-es-events.sh -t 2h -e EXEC,FORK -o events.jsongenerate-sigma-rule.py - Interactive Sigma rule generator
./scripts/generate-sigma-rule.pyconvert-detection.py - Detection format converter
./scripts/convert-detection.py -o sigma detection.splAll scripts are fully documented with --help flags and include:
See scripts/README.md for complete documentation, workflows, and troubleshooting.
Suspicious indicators:
- Unsigned or ad-hoc signed
- Execution from /tmp, /var/tmp, ~/Downloads
- Unusual parent-child relationship
- Suspicious command-line arguments (curl | bash, base64, etc.)
- Network activity immediately after execution
Key indicators:
- Launch agent/daemon creation (BTM events)
- Plist modifications in LaunchAgents/LaunchDaemons
- Shell profile modifications (.bashrc, .zshrc)
- Login items additions
- Unusual RunAtLoad + KeepAlive combinations
Monitor:
- SUDO/SU events (userspace)
- SETUID/SETGID events (kernel - more reliable)
- SUID binary creation
- TCC database modifications
- Authorization Service abuse
Critical detections:
- Quarantine attribute removal (com.apple.quarantine)
- Code signature invalidation (CS_INVALIDATED)
- Process injection (REMOTE_THREAD_CREATE, GET_TASK)
- File deletion (UNLINK for logs, security files)
High-value detections:
- Keychain file access (.keychain, .keychain-db)
- Browser credential file access (Login Data, Cookies)
- Memory access to security daemons (GET_TASK on securityd)
- Security command execution (dump-keychain)
Scenario: User asks "How do I detect dylib hijacking on macOS?"
Response Process:
Understand the technique:
references/attack-macos.md → T1574.006Identify telemetry:
Provide detection logic:
references/splunk-detection-patterns.mdreferences/sigma-macos.mdreferences/endpoint-security-framework.mdInclude filters:
Provide triage guidance:
This skill should be invoked for:
It provides expert knowledge on macOS security instrumentation, adversary behaviors, and detection engineering specific to the Apple ecosystem.
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract"
curl -s "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
The Frontend for Agents & Generative UI. React + Angular
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-09T23:06:25.207Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "cause",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:cause|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"category": "integration",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "vendor",
"label": "Vendor",
"value": "Null Event",
"category": "vendor",
"href": "https://github.com/null-event/macos-detect-and-respond-skills",
"sourceUrl": "https://github.com/null-event/macos-detect-and-respond-skills",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T03:15:56.674Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T03:15:56.674Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true,
"metadata": {}
}
]Sponsored
Ads related to macos-detect-and-respond and adjacent AI workflows.