LOLMac

LOLMac is a curated list of macOS binaries that can be used to bypass local security restrictions in misconfigured systems.

The project collects legitimate functions of macOS binaries that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks.

It is important to note that this is not a list of exploits, and the programs listed here are not vulnerable per se, rather, LOLMac is a compendium about how to live off the land when you only have certain binaries available.

LOLMac is a collaborative project created by Security Researchers where everyone can contribute with additional binaries and techniques.

If you are looking for Windows binaries you should visit LOLBAS.

💡 Search tips: Use binary_name to find specific binaries, +function to search functions, or combine them like plutil +file-read
Showing 3 of 3 binaries
Binary Functions
dscl
File read Execution Sudo
osascript
Execution File read File write Sudo
plutil
Execution File read