v1.2 (08/04/2026) patch note
Summary
- The total number of documented mechanisms increased from
31to39(+8 rows, no removals).
UI / UX
- Better colors
Added
- Added a
Privileged Helper Toolsentry covering the classic SMJobBless layout (/Library/PrivilegedHelperTools+ matching/Library/LaunchDaemonsplist) and modern bundle-embedded helpers under<App>.app/Contents/Library/LaunchServices. - Added an
SSH rcentry for~/.ssh/rcand chained payload drops commonly staged under~/.security/. - Added a
Calendar Alerts / EventKitentry for alarm-based execution triggers, covering~/Library/Calendars/,Calendar Cache, and~/Library/Preferences/com.apple.iCal.plist. - Added a
Finder Sync Extensionsentry for.appexbundles registered viapluginkit. - Added an
Application Support helpersentry for suspicious executables, scripts, and launch-style.plistfiles staged under~/Library/Application Support/. - Added an
Application startup scriptsentry for app-specific launch-script hooks such as~/.atom/init.coffee, iTerm2AutoLaunch/iTerm.py, and Sublime Text’ssublime.py. - Added an
App preference triggersentry for persistence hidden in user preferences:Docktiles,Terminalcommand strings, andScreen Savermodules. - Added a
TCC / Accessibility Grantsentry covering both user and systemTCC.dbas a capability-amplification surface adjacent to persistence.
Expanded Coverage
- Expanded
Shell init (zsh)andShell init (bash / sh)to include hidden helper drops under~/.security/. - Expanded
Cronto include hidden payload paths such as~/Public/Drop Box/.share.sh. - Expanded
Application / daemon plug-insto includeSublime Textpackages,~/.vim/plugin, and~/Library/Application Support/xbar/plugins. - Expanded
Login Hooksto include the root-scoped/private/var/root/Library/Preferences/com.apple.loginwindow.plistand shared payload staging under/Users/Shared/.security/. - Expanded
Periodic Jobsto include/usr/local/etc/periodic/{daily,weekly,monthly}alongside the system/etc/periodictree. - Expanded
KEXTsto include/System/Library/Extensionsalongside/Library/Extensions.
Light
Dark


Old versions
v1.1 (08/04/2026)
UI / UX
- Compacted
view-controlsto reduce visual footprint. - Strengthened the glass effect on the sticky controls panel.
- Trimmed some longer UI.
- Harmonized a few labels.
Scroll Behavior
- The helper text (
control-copy) now hides on scroll. - The
quick-navmoves up into the freed space to keep the header more compact. - The scrolled layout is now more responsive on intermediate screen widths.
Focus Mode
- Overview tags are now hidden in
Focus modefor a cleaner reading experience.
Overview / Mechanism
- Added and fixed badges for:
Scope,Source of Truth,Signal,Required Privilege,False Positive Risk - Standardized badge ordering.
- Fixed
False Positive Riskbadge color. - Fixed missing color styling for
Required PrivilegeandSource of Truth.
Download