Mac サーバのセキュリティとマルウェア
ファイアウォール、侵入防止、開放ポート監視、完全なマルウェア監査 — Mac とフリートのために。
多層防御:macOS アプリケーションファイアウォールと pf、fail2ban/CrowdSec、アラート付きの開放ポート監視、SSH 堅牢化、マルウェア監査ペイン(Gatekeeper/SIP/FileVault/XProtect・永続化・ClamAV・YARA・VirusTotal)。さらに高度なツール(Volatility 3・capa・CAPE/Cuckoo)と EDR フリートボード。
ネットワーク・境界・連携
Cloudflare(ゾーン・DNS・キャッシュ・トンネル)や OPNsense(REST API で操作)との緊密な連携 — さらに pfSense・OpenWrt・MikroTik RouterOS・UniFi など。UPnP や NAT-PMP でポートを開き、DDNS で変化する IP に追従、WireGuard・Tailscale・Headscale・NetBird・Nebula・ZeroTier でプライベートネットワークを構築、auth.md でパスワード不要のサービスログインを自動化。全プロトコル一覧はセキュリティリファレンスをご覧ください。
この用途で対応するサービス
この用途で FrontierStack がインストール・接続・監視できる 8 カテゴリ 216 サービス。アプリでこのプリセットを選ぶと、まとめて表示されます。
Security Tools73
- AbuseIPDB — Crowd-sourced IP reputation / blocklist (cloud API)
- AdGuard — Ad/tracker blocker app + AdGuard DNS & VPN (commercial)
- Admin By Request — Endpoint privilege management / just-in-time admin (agent + API)
- Airlock Digital — Application allowlisting & execution control (agent + API)
- AlienVault OTX — Open Threat Exchange IOC feed (cloud)
- AutoElevate (CyberFOX) — MSP privilege elevation & local-admin control (agent + API)
- BeyondTrust EPM — Endpoint Privilege Management for Mac (agent + API)
- binwalk — Firmware / embedded-file carving & analysis (self-hosted)
- Bitdefender GravityZone — Endpoint protection / EDR (macOS agent + API)
- BlockBlock — Monitor & block persistence in real time (self-hosted)
- Burp Suite — Web app security testing — intercepting proxy & scanner (macOS app)
- capa — Detect capabilities in executables (self-hosted)
- CAPE Sandbox — Malware sandbox w/ config extraction (self-hosted)
- ClamAV — Open-source antivirus engine (self-hosted)
- Cloudmersive — Virus-scan & content-protection API (cloud / self-host)
- Cortex — Observable analysers & responders engine (self-hosted)
- CrowdSec — Behavioural detection + IP blocking (crowd-sourced)
- CrowdStrike Falcon — Cloud-native EDR/XDR (macOS sensor + API)
- Cuckoo Sandbox — Automated malware-analysis sandbox (self-hosted)
- CyberArk EPM — Endpoint Privilege Manager (agent + API)
- CyberChef — The cyber-Swiss-army-knife for data
- Fail2ban — Bans IPs after suspicious activity (intrusion prevention)
- Fleet — Self-hosted osquery fleet manager (web UI + API)
- Fuzzilli — Coverage-guided JavaScript engine fuzzer (reviewed local binaries)
- GRR Rapid Response — Remote live-forensics / IR framework (self-hosted)
- Hands Off! — Per-app network + disk access control (app)
- Huntress — Managed EDR/MDR for SMB & MSPs (agent + API)
- Hybrid Analysis — Malware sandbox (Falcon Sandbox) — API
- IntelOwl — OSINT / threat-intel analysis platform (self-hosted)
- Jamf Protect — Mac-native endpoint security (agent + API)
- KnockKnock — Reveal persistently installed Mac software (self-hosted)
- Kolide — Device trust & posture (osquery-based agent + API)
- LimaCharlie — API-first SecOps cloud / EDR (agent + API)
- Little Snitch — Commercial network monitor & firewall (macOS app)
- LuLu — Free open-source outbound firewall (macOS app)
- Malwarebytes — Anti-malware (macOS app; business via Nebula API)
- Microsoft Defender for Endpoint — Microsoft EDR for macOS (agent + Graph API)
- MISP — Threat-intelligence sharing platform (self-hosted)
- Murus — GUI front-end for the macOS pf firewall (app)
- NetBarrier — Two-way macOS firewall (Intego, app)
- Nuclei — Template-based vulnerability scanner (self-hosted CLI)
- oletools — Analyse malicious Office docs / OLE (self-hosted)
- OpenCTI — Cyber threat-intelligence platform (self-hosted)
- OpenEDR — Open-source endpoint detection & response (self-hosted)
- OpenPhish — Live phishing-URL feed (cloud)
- OpenVAS / Greenbone — Vulnerability scanning (self-hosted)
- OPSWAT MetaDefender — Multi-engine malware scanning & file CDR (self-hosted / API)
- osquery — Query your endpoint like a database (agent)
- OSSEC — Host-based IDS: log, file-integrity & rootkit monitoring
- OWASP ZAP — Open-source web-app security scanner (DAST) — spider, active scan, proxy
- Phishing Catcher — Catch phishing domains from CT logs (self-hosted)
- radare2 — Reverse-engineering framework / disassembler (self-hosted)
- Radio Silence — Lightweight macOS outbound firewall (app)
- Santa — macOS binary allowlisting / blocklisting (self-hosted)
- Security Onion — NSM + SIEM + IDS Linux distro (self-hosted)
- SentinelOne — Autonomous EDR/XDR (macOS agent + API)
- Snort — The classic network IDS (self-hosted)
- Sophos Central — Endpoint protection / MDR (macOS agent + API)
- Strix — AI-assisted penetration testing from the local CLI
- Suricata — High-performance IDS/IPS engine (self-hosted)
- TheHive — Security incident-response platform (self-hosted)
- ThreatLocker — Zero Trust app allowlisting & endpoint control (agent + cloud portal)
- URLhaus — Malware-URL feed & lookup API (cloud · abuse.ch)
- Vallum — Per-app outbound firewall & throttle (app)
- Velociraptor — Endpoint visibility & DFIR hunting (self-hosted)
- Vibe Proxy — AI-assisted web security testing & intercepting proxy
- VirusTotal — Multi-engine file/URL reputation (API)
- Volatility 3 — Memory-forensics framework (self-hosted)
- Wazuh — Open-source SIEM & XDR (self-hosted)
- Yakit — Open-source web security testing platform & MITM (macOS app)
- YARA — Pattern-matching engine for malware (self-hosted)
- YARA-X — YARA rewritten in Rust — faster CLI scanner (self-hosted)
- Zeek — Network security monitor / traffic analysis (self-hosted)
Policy, Compliance & Governance46
- Amundsen — Open-source data discovery & metadata engine (self-hosted)
- Apache Atlas — Metadata & governance for the Hadoop/data ecosystem (self-hosted)
- Aserto / Topaz — Authorization built on OPA + Zanzibar (self-hosted / cloud)
- AuditBoard — Connected risk, audit & compliance platform (cloud)
- Authzed / SpiceDB — Zanzibar-style permissions database (self-hosted / cloud)
- AWS Config — Native AWS resource configuration & compliance (API)
- AWS Security Hub — Aggregated AWS security findings & standards (API)
- BigID — Data discovery, privacy & governance at scale (cloud)
- Checkov — Static policy scanning for IaC (self-hosted CLI)
- Cloud Custodian — Rules engine for cloud governance & remediation (CLI)
- CloudQuery — Cloud asset inventory as SQL (self-hosted CLI)
- Conftest — Test config files against OPA/Rego policies (CLI)
- DataGrail — Privacy platform — DSR & data mapping automation (cloud)
- DataHub — Open-source metadata platform & data catalogue (self-hosted)
- Drata — Continuous compliance automation & audit readiness (cloud)
- Eramba — Open-source GRC platform (self-hosted)
- Everlaw — Cloud litigation & eDiscovery platform (cloud)
- Google Vault — Retention, legal hold & eDiscovery for Google Workspace (cloud)
- HashiCorp Sentinel — Policy as code for the HashiCorp stack (CLI)
- Hyperproof — Compliance operations & evidence management (cloud)
- immudb — Immutable, cryptographically-verifiable database / audit log (self-hosted)
- Kyverno — Kubernetes-native policy engine, no new language (self-hosted)
- LogicGate Risk Cloud — No-code GRC & risk workflow platform (cloud)
- Logikcull — Self-service eDiscovery & legal hold (cloud, Reveal)
- Microsoft Purview — Data governance, compliance, retention & eDiscovery (cloud)
- MineOS — Data-governance & privacy operations platform (cloud)
- OneTrust — Privacy, GRC & data governance suite (cloud)
- OPA Gatekeeper — OPA policy admission controller for Kubernetes (self-hosted)
- Open Policy Agent (OPA) — General-purpose policy engine, Rego (self-hosted CLI)
- OpenControl — Compliance-as-code documentation toolkit (self-hosted CLI)
- OpenFGA — Open-source fine-grained authorization (Zanzibar-style, self-hosted)
- OpenGRC — Open-source governance, risk & compliance (self-hosted)
- OpenMetadata — Open-source metadata, catalogue & lineage platform (self-hosted)
- Osano — Consent management & privacy compliance (cloud)
- Permify — Open-source fine-grained authorization service (self-hosted)
- Prowler — Open-source multi-cloud security & compliance scanner (CLI)
- Scout Suite — Multi-cloud security-auditing tool (CLI)
- Secureframe — Compliance automation across 40+ frameworks (cloud)
- Securiti — Data privacy, security & governance platform (cloud)
- SimpleRisk — Open-source risk management (self-hosted)
- Smarsh — Communications capture, archiving & supervision (cloud)
- Sprinto — Compliance automation for fast-moving teams (cloud)
- Steampipe — Query cloud APIs with SQL + compliance mods (CLI)
- Thoropass — Compliance + audit in one (formerly Laika, cloud)
- Transcend — Privacy & data-rights automation, incl. AI governance (cloud)
- Vanta — Automated compliance — SOC 2, ISO 27001, HIPAA, GDPR (cloud)
Monitoring28
- Alertmanager — Route and deduplicate Prometheus alerts (self-hosted)
- Beszel — Lightweight server monitoring hub + agents
- Checkmk — Auto-discovering IT monitoring (self-hosted)
- Datadog — Hosted metrics, logs, traces and synthetics (SaaS)
- Dynatrace — Enterprise observability and AIOps platform
- Glances — Cross-platform system monitor (web/API)
- GoAccess — Real-time access-log analyser (CLI/HTML)
- Grafana — Dashboards for any data source (self-hosted)
- Healthchecks.io — Cron & heartbeat monitoring (cloud or self-hosted)
- Homepage — Self-hosted services dashboard (gethomepage.dev)
- Honeycomb — Observability for high-cardinality events and traces
- Matomo — Full-featured self-hosted web analytics
- Nagios Core — The classic check-based monitor (self-hosted)
- Netdata — Real-time system metrics dashboard
- New Relic — Hosted APM, infrastructure and logs (SaaS)
- Node Exporter — Unix host metrics for Prometheus (self-hosted)
- NUT (Network UPS Tools) — UPS monitoring server (upsd) for many devices
- PeaNUT — Modern web dashboard for NUT UPS servers
- Plausible — Lightweight, privacy-first analytics
- Prometheus — Time-series metrics & alerting (self-hosted)
- Scrutiny — S.M.A.R.T. drive health dashboard
- Sentry — Error tracking and performance monitoring
- Speedtest Tracker — Scheduled internet speed tests + history
- Umami — Simple, privacy-focused analytics (Node)
- Uptime Kuma — Self-hosted uptime monitor
- UptimeRobot — Cloud uptime/SSL monitoring with status pages
- Windows Exporter — Windows host metrics for Prometheus (remote)
- Zabbix — Enterprise monitoring — agents, SNMP, triggers (self-hosted)
Routers & Firewalls19
- Cisco Secure Firewall — Cisco NGFW (Firepower/ASA) — FMC/FDM API (commercial)
- Cradlepoint — Cellular/5G edge routers (NCOS + NetCloud)
- Firewalla — Home/SMB security router (cloud MSP API)
- FortiGate — Fortinet next-gen firewall — REST API (commercial)
- IPFire — Hardened open-source Linux firewall (web UI)
- MikroTik (RouterOS) — RouterOS devices — REST API (v7+)
- OpenWrt — Open-source router firmware (LuCI / ubus)
- OPNsense — Open-source firewall/router OS (REST API)
- Palo Alto Networks — PAN-OS next-gen firewall — XML/REST API (commercial)
- Peplink — SD-WAN routers with multi-WAN failover/bonding
- pfSense — FreeBSD firewall/router OS (REST via package)
- PoE Switch (RFC 3621) — Managed PoE switch — port power, budget & cycling over SNMP
- Sophos Firewall — Next-gen firewall appliance — web UI + API (commercial)
- UFW (Uncomplicated Firewall) — Easy iptables/nftables host firewall for Linux servers (manage over SSH)
- UniFi — Ubiquiti Cloud Gateway / Dream Machine + Network controller
- UniFi OS Server — Self-hosted UniFi OS — run the full stack on your own Mac or Linux box
- Untangle / Arista NG Firewall — Debian network gateway — web admin (commercial)
- VyOS — Linux network OS — unified CLI + HTTPS API
- WatchGuard Firebox — Fireware firewall appliance — web UI + Cloud API (commercial)
Secrets Scanning & Supply Chain Security16
- Chainguard — Minimal, low/zero-CVE container images (cloud + chainctl)
- Cosign — Sign & verify container images and artifacts (self-hosted CLI)
- Dependabot — Automated dependency-update & security PRs (GitHub)
- GitGuardian — Secrets detection across code & CI (cloud + ggshield CLI)
- Gitleaks — Open-source secrets scanner for git repos (self-hosted CLI)
- Grype — Fast vulnerability scanner for images & SBOMs (self-hosted CLI)
- Lynis — Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)
- OSV-Scanner — Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)
- Renovate — Automated dependency updates, any platform (self-hosted / app)
- Semgrep Supply Chain — SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)
- Sigstore — Keyless signing ecosystem — Cosign, Fulcio, Rekor (self-hosted / public)
- Snyk — Developer security — code, deps, containers & IaC (cloud + CLI)
- Socket — Proactive dependency / supply-chain attack detection (cloud + CLI)
- Syft — Generate SBOMs from images & filesystems (self-hosted CLI)
- Trivy — All-in-one vuln, secret, IaC & SBOM scanner (self-hosted CLI)
- TruffleHog — Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)
Mesh Networking15
- AREDN — Amateur-radio high-speed mesh (ham licence)
- B.A.T.M.A.N.-adv — Layer-2 community Wi-Fi mesh routing (Linux)
- Babel (babeld) — Robust distance-vector mesh routing protocol
- Briar — P2P messaging over Tor, Wi-Fi & Bluetooth
- cjdns / Hyperboria — Encrypted IPv6 mesh routing (source-routed)
- Meshtastic — LoRa mesh radio for text & location (off-grid)
- Nomad Network (NomadNet) — Resilient comms over Reticulum (pages, files, messaging)
- OLSR (olsrd) — Optimized Link State Routing for MANETs
- qaul — Internet-independent P2P mesh messaging app
- Ratspeak — Private, account-free mesh messaging (Reticulum-based)
- Reticulum — Cryptography-based mesh networking stack (any medium)
- RNode LoRa Devices — Open LoRa radio interface for Reticulum (flash & configure)
- Serval Mesh — Off-grid mesh comms (Serval Project)
- Sideband — LXMF messaging app over Reticulum (desktop/mobile)
- Yggdrasil — Self-arranging encrypted IPv6 mesh (experimental)
Secrets & Vaults10
- 1Password — Password manager with developer secrets API (cloud)
- 1Password SCIM Bridge — Automated 1Password user provisioning (self-hosted bridge)
- Bitwarden — Password manager — cloud or official self-host
- Doppler — Hosted secrets & config manager (cloud)
- HashiCorp Vault — Secrets, PKI & dynamic credentials (self-hosted)
- Infisical — Open-source secrets for app configs (cloud or self-hosted)
- Keeper Security — Password manager & Secrets Manager (cloud API)
- Let's Encrypt — Free TLS certificates via ACME — health & renewal monitor
- Step CA — Your own private certificate authority (self-hosted)
- Vaultwarden — Self-hosted Bitwarden-compatible server (Docker)
Logging & Observability9
- Dozzle — Live Docker container log viewer
- Elastic Cloud — Hosted Elasticsearch, Kibana and observability
- Fluent Bit — Ultra-light log forwarder (self-hosted)
- Graylog — Centralized log management (self-hosted)
- Kibana — ELK's search & dashboard UI (self-hosted)
- Logstash — ELK's ingest & transform pipeline (self-hosted)
- Loki — Grafana's log store — like Prometheus, for logs (self-hosted)
- Splunk — Enterprise log search, SIEM and observability
- Vector — High-performance logs/metrics pipeline (self-hosted)
すべてをひとつの Mac アプリで。
FrontierStack は、ローカルでもフリート全体でも、スタック全体のインストール・監視・保護をひとつのネイティブ macOS アプリで行います。
FrontierStack をダウンロード