macOS Persistence Cheatsheet#
April 2026
- A practical DFIR-focused cheatsheet for identifying, triaging, and reviewing macOS persistence mechanisms. With additional context such as scope, required privilege, source of truth, signal level, false-positive risk and review guidance.
- Light & dark theme.
- Covers 39 macOS persistence mechanisms across core launch, shell and scheduled execution, extensions and handlers, adjacent and legacy techniques, and profiles / MDM.
- Includes search and interactive legend filters to quickly narrow mechanisms by scope, required privilege, source of truth, signal, and false-positive risk.
- Provides quick navigation, reading/compact density modes, and a focus mode.
- Includes a synchronized mechanism overview to scan all documented techniques at a glance.
- Documents artifact paths, collection and triage notes, execution triggers, and review guidance for each mechanism.

https://github.com/jaybird1291/macOS-persistence-cheatsheet
Anki LLM Review Stats Exporter#
December 2025 - December 2025
- Export your Anki review history (revlog) as JSONL so you can analyze it with an LLM (ChatGPT, Claude, local models, etc.) without using any API
- Python
https://github.com/jaybird1291/anki-llm-review-stats-exporter
Automatization of macOS malware detection with LLMs#
July 2025 - July 2025
- Did in Martina Tivadar’s training at OFTW 2025
- GitHub Actions, Python, Apple’s Endpoint Security framework, OpenAI API
https://github.com/jaybird1291/OFTW-v3-training
Self-Hosted Infrastructure#
June 2023 - now
- Professional Server (HP ProLiant DL380 Gen9 2U) running Proxmox
- Firewall running OPNsense
- Self-hosted services and tools: VPN, Security Onion, Wazuh, Cuckoo Sandbox, GitLab, CTF machines, various labs (red team / blue team)
- A special Malware Analysis lab & OSINT lab with security, privacy and OPSEC in mind
- Architecture, network segmentation, IPS/IDS integration, load balancing, SRE, VPN
CTF Challenge Creator#
June 2024 - Juin 2024
Creation of two radio challenges (misc easy and medium) for the “PwnMe CTF 2024”.
Side Quest - Toolkit Network Forensic & Malware Analysis#
Feb. 2024 - June 2024
Our Side Quest is a collaborative student project designed to provide a powerful toolkit for network forensic analysis and malware analysis. This repository contains two sub-projects that focus on different aspects of investigation:
- Network Forensic Analysis: Tools for analyzing network traffic captured in PCAP files.
- Malware Analysis: Tools for dissecting binary files to uncover hidden information and detect malicious characteristics.
https://github.com/jaybird1291/toolkit-network-forensic-malware-analysis-sidequest