Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
XPRTestSuite — A collection of scripts and documents to help future XProtect Remediator (XPR) research | Kitploit
Tools/GitHubGitHub/ffri/xprtestsuite
Reverse EngineeringMalware AnalysisPapers & ResearchLearning & EducationLabs & Practice
GitHubffri/xprtestsuite

XPRTestSuite

A collection of scripts and documents to help future XProtect Remediator (XPR) research

View Repository
12170 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

XProtect Remediator Test Suite

A collection of scripts and documents to help future XProtect Remediator (XPR) research, presented at Black Hat USA 2025

About This Repository

This repository contains:

  • The scripts to create harmless minimal files and processes that reproduce the remediation of each scanning module of XPR
  • The documents that describe the reverse-engineered XPR remediation (or detection) logic using the RemediationBuilder DSL

These scripts and documents were created for verification purposes of our reverse engineering of XPR. We hope that this repository will be useful for security researchers who conduct XPR analysis in the future and want to understand under what conditions remediation occurs.

NOTE: Please run these scripts in a virtualized environment.

Preparation

To reveal <private> entries in the Unified Logs, follow the steps outlined in the article below.

Unified Logs: How to Enable Private Data

How to Use

Navigate to cd TestSuite/<module_name> and execute ./run.sh.

cd TestSuite/Adload
./run.sh --test-case service

Some test cases require root privileges to run. However, they are basically designed to run with user privileges.

cd TestSuite/RedPine
sudo ./run.sh --test-case redpine

To reproduce XPR remediation/remediation, open a new terminal and run

/Library/Apple/System/Library/CoreServices/XProtect.app/Contents/MacOS/XProtect

or

/Library/Apple/System/Library/CoreServices/XProtect.app/Contents/MacOS/XProtectRemediator<module_name> # (e.g., XProtectRemediatorAdload)

Verified Versions

Module NameVerified Version(s)ScriptDocument
Adload145✅✅
BadGacha133, 145✅✅
Bundlore149✅✅
CardboardCutout145✅
ColdSnap145✅✅
Eicar145✅✅
KeySteal145✅✅
Pirrit145✅✅
RedPine141✅✅
RoachFlight145✅
RankStank145✅✅
SheepSwap145✅✅
SnowDrift145✅✅
WaterNet145✅✅

Author

Koh M. Nakagawa (@tsunek0h) © FFRI Security, Inc. 2025

License

Apache version 2.0

Download Tool