ホーム › ソリューション › Mac サーバのセキュリティとマルウェア

Mac サーバのセキュリティとマルウェア

ファイアウォール、侵入防止、開放ポート監視、完全なマルウェア監査 — Mac とフリートのために。

多層防御:macOS アプリケーションファイアウォールと pf、fail2ban/CrowdSec、アラート付きの開放ポート監視、SSH 堅牢化、マルウェア監査ペイン(Gatekeeper/SIP/FileVault/XProtect・永続化・ClamAV・YARA・VirusTotal)。さらに高度なツール(Volatility 3・capa・CAPE/Cuckoo)と EDR フリートボード。

物理キーを確認するまで一切操作させない

Fleet ライセンスでは、App Lock に物理 FIDO2 セキュリティキーを必須にできます。パスワードロック設定の隣で Yubico YubiKey・Google Titan・FEITIAN ePass を登録すると、登録済みキーに触れるまで、外部の制御経路も含めて FrontierStack はロックされたままです。パスワードも設定していれば両方が必要です。保管用の予備を用意できるよう最大 3 本まで登録できます。対応する USB-C・Lightning・NFC モデルは、Apple のセキュリティキー画面を通じて iPhone/iPad アプリでも使えます。同じキーで、スマートフォンのペアリングや権限の引き上げを承認し、スマートフォンがシークレットやリモートシェルを使う前に短いセッションを開き、AI のスクリプトシークレットをタッチなしでは読めないよう暗号化したり、サーバへの SSH に必須にしたりできます(一度のタッチで開いたセッションを監視とターミナルが共有します)。許可すれば、アプリを閉じて作業するエージェントも、登録済みのキーが挿さっている間は読み取り専用のチェックを実行でき、キーを抜けばすぐに止まります。

ネットワーク・境界・連携

Cloudflare(ゾーン・DNS・キャッシュ・トンネル)や OPNsense(REST API で操作)との緊密な連携 — さらに pfSense・OpenWrt・MikroTik RouterOS・UniFi など。UPnP や NAT-PMP でポートを開き、DDNS で変化する IP に追従、WireGuard・Tailscale・Headscale・NetBird・Nebula・ZeroTier でプライベートネットワークを構築、auth.md でパスワード不要のサービスログインを自動化。全プロトコル一覧はセキュリティリファレンスをご覧ください。

この用途で対応するサービス

この用途で FrontierStack がインストール・接続・監視できる 8 カテゴリ 237 サービス。アプリでこのプリセットを選ぶと、まとめて表示されます。

カテゴリから探す (8)
Security Tools81
  • AbuseIPDB — Crowd-sourced IP reputation / blocklist (cloud API)
  • AdGuard — Ad/tracker blocker app + AdGuard DNS & VPN (commercial)
  • Admin By Request — Endpoint privilege management / just-in-time admin (agent + API)
  • Airlock Digital — Application allowlisting & execution control (agent + API)
  • AlienVault OTX — Open Threat Exchange IOC feed (cloud)
  • AutoElevate (CyberFOX) — MSP privilege elevation & local-admin control (agent + API)
  • BeyondTrust EPM — Endpoint Privilege Management for Mac (agent + API)
  • binwalk — Firmware / embedded-file carving & analysis (self-hosted)
  • Bitdefender GravityZone — Endpoint protection / EDR (macOS agent + API)
  • BlockBlock — Monitor & block persistence in real time (self-hosted)
  • Burp Suite — Web app security testing — intercepting proxy & scanner (macOS app)
  • capa — Detect capabilities in executables (self-hosted)
  • CAPE Sandbox — Malware sandbox w/ config extraction (self-hosted)
  • Censys — Internet-wide host & certificate search (cloud API)
  • ClamAV — Open-source antivirus engine (self-hosted)
  • Cloudmersive — Virus-scan & content-protection API (cloud / self-host)
  • Cortex — Observable analysers & responders engine (self-hosted)
  • CrowdSec — Behavioural detection + IP blocking (crowd-sourced)
  • CrowdStrike Falcon — Cloud-native EDR/XDR (macOS sensor + API)
  • Cuckoo Sandbox — Automated malware-analysis sandbox (self-hosted)
  • CyberArk EPM — Endpoint Privilege Manager (agent + API)
  • CyberChef — The cyber-Swiss-army-knife for data
  • Fail2ban — Bans IPs after suspicious activity (intrusion prevention)
  • Fleet — Self-hosted osquery fleet manager (web UI + API)
  • Fuzzilli — Coverage-guided JavaScript engine fuzzer (reviewed local binaries)
  • Google Safe Browsing — Is your site flagged as malicious by Chrome? (cloud API)
  • GreyNoise — Is this IP scanning everyone, or targeting you? (cloud API)
  • GRR Rapid Response — Remote live-forensics / IR framework (self-hosted)
  • Hands Off! — Per-app network + disk access control (app)
  • Huntress — Managed EDR/MDR for SMB & MSPs (agent + API)
  • Hybrid Analysis — Malware sandbox (Falcon Sandbox) — API
  • Intego NetBarrier — Intego's two-way Mac firewall (NetBarrier X9 / Intego ONE)
  • IntelOwl — OSINT / threat-intel analysis platform (self-hosted)
  • Jamf Protect — Mac-native endpoint security (agent + API)
  • KnockKnock — Reveal persistently installed Mac software (self-hosted)
  • Kolide — Device trust & posture (osquery-based agent + API)
  • LimaCharlie — API-first SecOps cloud / EDR (agent + API)
  • Little Snitch — Commercial network monitor & firewall (macOS app)
  • LuLu — Free open-source outbound firewall (macOS app)
  • Malwarebytes — Anti-malware (macOS app; business via Nebula API)
  • Microsoft Defender for Endpoint — Microsoft EDR for macOS (agent + Graph API)
  • MISP — Threat-intelligence sharing platform (self-hosted)
  • Mozilla Observatory — Graded HTTP header & TLS scan for your own sites (free API)
  • Murus — GUI front-end for the macOS pf firewall (app)
  • NetBarrier — Two-way macOS firewall (Intego, app)
  • Nuclei — Template-based vulnerability scanner (self-hosted CLI)
  • oletools — Analyse malicious Office docs / OLE (self-hosted)
  • OpenCTI — Cyber threat-intelligence platform (self-hosted)
  • OpenEDR — Open-source endpoint detection & response (self-hosted)
  • OpenPhish — Live phishing-URL feed (cloud)
  • OpenVAS / Greenbone — Vulnerability scanning (self-hosted)
  • OPSWAT MetaDefender — Multi-engine malware scanning & file CDR (self-hosted / API)
  • osquery — Query your endpoint like a database (agent)
  • OSSEC — Host-based IDS: log, file-integrity & rootkit monitoring
  • OWASP ZAP — Open-source web-app security scanner (DAST) — spider, active scan, proxy
  • pfBlockerNG — IP & DNS blocklists for pfSense (DNSBL ad/malware blocking)
  • Phishing Catcher — Catch phishing domains from CT logs (self-hosted)
  • radare2 — Reverse-engineering framework / disassembler (self-hosted)
  • Radio Silence — Lightweight macOS outbound firewall (app)
  • Santa — macOS binary allowlisting / blocklisting (self-hosted)
  • SentinelOne — Autonomous EDR/XDR (macOS agent + API)
  • Shodan — Search engine for internet-exposed hosts and services (cloud API)
  • Snort — The classic network IDS (self-hosted)
  • Sophos Central — Endpoint protection / MDR (macOS agent + API)
  • Strix — AI-assisted penetration testing from the local CLI
  • Suricata — High-performance IDS/IPS engine (self-hosted)
  • TheHive — Security incident-response platform (self-hosted)
  • ThreatLocker — Zero Trust app allowlisting & endpoint control (agent + cloud portal)
  • URLhaus — Malware-URL feed & lookup API (cloud · abuse.ch)
  • urlscan.io — Sandboxed URL scanning — see what a link really does (cloud API)
  • Vallum — Per-app outbound firewall & throttle (app)
  • Velociraptor — Endpoint visibility & DFIR hunting (self-hosted)
  • Vibe Proxy — AI-assisted web security testing & intercepting proxy
  • VirusTotal — Multi-engine file/URL reputation (API)
  • Volatility 3 — Memory-forensics framework (self-hosted)
  • Wireshark — Packet capture and protocol analysis for network diagnosis
  • Yakit — Open-source web security testing platform & MITM (macOS app)
  • YARA — Pattern-matching engine for malware (self-hosted)
  • YARA-X — YARA rewritten in Rust — faster CLI scanner (self-hosted)
  • Zeek — Network security monitor / traffic analysis (self-hosted)
  • Zenarmor — Next-gen firewall / DPI layer for OPNsense & pfSense (formerly Sensei)
Policy, Compliance & Governance46
  • Amundsen — Open-source data discovery & metadata engine (self-hosted)
  • Apache Atlas — Metadata & governance for the Hadoop/data ecosystem (self-hosted)
  • Aserto / Topaz — Authorization built on OPA + Zanzibar (self-hosted / cloud)
  • AuditBoard — Connected risk, audit & compliance platform (cloud)
  • Authzed / SpiceDB — Zanzibar-style permissions database (self-hosted / cloud)
  • AWS Config — Native AWS resource configuration & compliance (API)
  • AWS Security Hub — Aggregated AWS security findings & standards (API)
  • BigID — Data discovery, privacy & governance at scale (cloud)
  • Checkov — Static policy scanning for IaC (self-hosted CLI)
  • Cloud Custodian — Rules engine for cloud governance & remediation (CLI)
  • CloudQuery — Cloud asset inventory as SQL (self-hosted CLI)
  • Conftest — Test config files against OPA/Rego policies (CLI)
  • DataGrail — Privacy platform — DSR & data mapping automation (cloud)
  • DataHub — Open-source metadata platform & data catalogue (self-hosted)
  • Drata — Continuous compliance automation & audit readiness (cloud)
  • Eramba — Open-source GRC platform (self-hosted)
  • Everlaw — Cloud litigation & eDiscovery platform (cloud)
  • Google Vault — Retention, legal hold & eDiscovery for Google Workspace (cloud)
  • HashiCorp Sentinel — Policy as code for the HashiCorp stack (CLI)
  • Hyperproof — Compliance operations & evidence management (cloud)
  • immudb — Immutable, cryptographically-verifiable database / audit log (self-hosted)
  • Kyverno — Kubernetes-native policy engine, no new language (self-hosted)
  • LogicGate Risk Cloud — No-code GRC & risk workflow platform (cloud)
  • Logikcull — Self-service eDiscovery & legal hold (cloud, Reveal)
  • Microsoft Purview — Data governance, compliance, retention & eDiscovery (cloud)
  • MineOS — Data-governance & privacy operations platform (cloud)
  • OneTrust — Privacy, GRC & data governance suite (cloud)
  • OPA Gatekeeper — OPA policy admission controller for Kubernetes (self-hosted)
  • Open Policy Agent (OPA) — General-purpose policy engine, Rego (self-hosted CLI)
  • OpenControl — Compliance-as-code documentation toolkit (self-hosted CLI)
  • OpenFGA — Open-source fine-grained authorization (Zanzibar-style, self-hosted)
  • OpenGRC — Open-source governance, risk & compliance (self-hosted)
  • OpenMetadata — Open-source metadata, catalogue & lineage platform (self-hosted)
  • Osano — Consent management & privacy compliance (cloud)
  • Permify — Open-source fine-grained authorization service (self-hosted)
  • Prowler — Open-source multi-cloud security & compliance scanner (CLI)
  • Scout Suite — Multi-cloud security-auditing tool (CLI)
  • Secureframe — Compliance automation across 40+ frameworks (cloud)
  • Securiti — Data privacy, security & governance platform (cloud)
  • SimpleRisk — Open-source risk management (self-hosted)
  • Smarsh — Communications capture, archiving & supervision (cloud)
  • Sprinto — Compliance automation for fast-moving teams (cloud)
  • Steampipe — Query cloud APIs with SQL + compliance mods (CLI)
  • Thoropass — Compliance + audit in one (formerly Laika, cloud)
  • Transcend — Privacy & data-rights automation, incl. AI governance (cloud)
  • Vanta — Automated compliance — SOC 2, ISO 27001, HIPAA, GDPR (cloud)
Monitoring46
  • Alertmanager — Route and deduplicate Prometheus alerts (self-hosted)
  • AppSignal — Application errors, performance, uptime and deploys (SaaS)
  • Atatus — APM, logs, infrastructure and real-user monitoring (SaaS)
  • Atera — RMM, patching, ticketing and automation (SaaS)
  • Beszel — Lightweight server monitoring hub + agents
  • Checkmk — Auto-discovering IT monitoring (self-hosted)
  • Datadog — Hosted metrics, logs, traces and synthetics (SaaS)
  • Dynatrace — Enterprise observability and AIOps platform
  • FirstWave NMIS — Open network fault, performance and configuration monitoring
  • Glances — Cross-platform system monitor (web/API)
  • GoAccess — Real-time access-log analyser (CLI/HTML)
  • Grafana — Dashboards for any data source (self-hosted)
  • Healthchecks.io — Cron & heartbeat monitoring (cloud or self-hosted)
  • Homepage — Self-hosted services dashboard (gethomepage.dev)
  • Honeycomb — Observability for high-cardinality events and traces
  • Infraon IMS — Unified infrastructure, network and configuration monitoring
  • LibreNMS — Auto-discovering SNMP network monitoring (switches, routers, servers)
  • ManageEngine Applications Manager — Application, server, VM and capacity monitoring
  • ManageEngine OpManager Nexus — Unified network, server and IT operations management
  • Matomo — Full-featured self-hosted web analytics
  • N-able N-central — Unified endpoint management, RMM and patching
  • Nagios Core — The classic check-based monitor (self-hosted)
  • Naverisk RMM & PSA — Cross-platform RMM, service desk and PSA
  • Netdata — Real-time system metrics dashboard
  • Netreo — Full-stack infrastructure and business-service observability
  • New Relic — Hosted APM, infrastructure and logs (SaaS)
  • NinjaOne — Endpoint monitoring, patching and automation (SaaS RMM)
  • Node Exporter — Unix host metrics for Prometheus (self-hosted)
  • ntopng — Live traffic analysis — who is talking to whom, and how much
  • NUT (Network UPS Tools) — Free, open-source UPS monitoring server (upsd)
  • Paessler PRTG — Network, server and infrastructure monitoring (Windows or hosted)
  • Pandora FMS — Infrastructure, application, log and synthetic monitoring
  • PeaNUT — Modern web dashboard for NUT UPS servers
  • Plausible — Lightweight, privacy-first analytics
  • Prometheus — Time-series metrics & alerting (self-hosted)
  • Pulseway — Mobile-first RMM, patching and endpoint automation
  • Scrutiny — S.M.A.R.T. drive health dashboard
  • Sentry — Error tracking and performance monitoring
  • Server Density — Hosted server, service and container monitoring
  • Site24x7 — Infrastructure, application, network and experience monitoring (SaaS)
  • Speedtest Tracker — Scheduled internet speed tests + history
  • Umami — Simple, privacy-focused analytics (Node)
  • Uptime Kuma — Self-hosted uptime monitor
  • UptimeRobot — Cloud uptime/SSL monitoring with status pages
  • Windows Exporter — Windows host metrics for Prometheus (remote)
  • Zabbix — Enterprise monitoring — agents, SNMP, triggers (self-hosted)
Routers & Firewalls19
  • Cisco Secure Firewall — Cisco NGFW (Firepower/ASA) — FMC/FDM API (commercial)
  • Cradlepoint — Cellular/5G edge routers (NCOS + NetCloud)
  • Firewalla — Home/SMB security router (cloud MSP API)
  • FortiGate — Fortinet next-gen firewall — REST API (commercial)
  • IPFire — Hardened open-source Linux firewall (web UI)
  • MikroTik (RouterOS) — RouterOS devices — REST API (v7+)
  • OpenWrt — Open-source router firmware (LuCI / ubus)
  • OPNsense — Open-source firewall/router OS (REST API)
  • Palo Alto Networks — PAN-OS next-gen firewall — XML/REST API (commercial)
  • pfSense — FreeBSD firewall/router OS (REST via package)
  • PoE Switch (RFC 3621) — Managed PoE switch — port power, budget & cycling over SNMP
  • Sophos Firewall — Next-gen firewall appliance — web UI + API (commercial)
  • UFW (Uncomplicated Firewall) — Easy iptables/nftables host firewall for Linux servers (manage over SSH)
  • UniFi — Ubiquiti Cloud Gateway / Dream Machine / Superlink + Network controller
  • UniFi OS Server — Self-hosted UniFi OS — run the full stack on your own Mac or Linux box
  • Untangle / Arista NG Firewall — Debian network gateway — web admin (commercial)
  • VyOS — Linux network OS — unified CLI + HTTPS API
  • WatchGuard Firebox — Fireware firewall appliance — web UI + Cloud API (commercial)
Secrets Scanning & Supply Chain Security16
  • Chainguard — Minimal, low/zero-CVE container images (cloud + chainctl)
  • Cosign — Sign & verify container images and artifacts (self-hosted CLI)
  • Dependabot — Automated dependency-update & security PRs (GitHub)
  • GitGuardian — Secrets detection across code & CI (cloud + ggshield CLI)
  • Gitleaks — Open-source secrets scanner for git repos (self-hosted CLI)
  • Grype — Fast vulnerability scanner for images & SBOMs (self-hosted CLI)
  • Lynis — Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)
  • OSV-Scanner — Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)
  • Renovate — Automated dependency updates, any platform (self-hosted / app)
  • Semgrep Supply Chain — SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)
  • Sigstore — Keyless signing ecosystem — Cosign, Fulcio, Rekor (self-hosted / public)
  • Snyk — Developer security — code, deps, containers & IaC (cloud + CLI)
  • Socket — Proactive dependency / supply-chain attack detection (cloud + CLI)
  • Syft — Generate SBOMs from images & filesystems (self-hosted CLI)
  • Trivy — Vuln, secret, IaC & SBOM scanner (self-hosted CLI)
  • TruffleHog — Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)
Mesh Networking15
  • AREDN — Amateur-radio high-speed mesh (ham licence)
  • B.A.T.M.A.N.-adv — Layer-2 community Wi-Fi mesh routing (Linux)
  • Babel (babeld) — Reliable distance-vector mesh routing protocol
  • Briar — P2P messaging over Tor, Wi-Fi & Bluetooth
  • cjdns / Hyperboria — Encrypted IPv6 mesh routing (source-routed)
  • Meshtastic — LoRa mesh radio for text & location (off-grid)
  • Nomad Network (NomadNet) — Resilient comms over Reticulum (pages, files, messaging)
  • OLSR (olsrd) — Optimized Link State Routing for MANETs
  • qaul — Internet-independent P2P mesh messaging app
  • Ratspeak — Private, account-free mesh messaging (Reticulum-based)
  • Reticulum — Cryptography-based mesh networking stack (any medium)
  • RNode LoRa Devices — Open LoRa radio interface for Reticulum (flash & configure)
  • Serval Mesh — Off-grid mesh comms (Serval Project)
  • Sideband — LXMF messaging app over Reticulum (desktop/mobile)
  • Yggdrasil — Self-arranging encrypted IPv6 mesh (experimental)
Secrets & Vaults10
  • 1Password — Password manager with developer secrets API (cloud)
  • 1Password SCIM Bridge — Automated 1Password user provisioning (self-hosted bridge)
  • Bitwarden — Password manager — cloud or official self-host
  • Doppler — Hosted secrets & config manager (cloud)
  • HashiCorp Vault — Secrets, PKI & dynamic credentials (self-hosted)
  • Infisical — Open-source secrets for app configs (cloud or self-hosted)
  • Keeper Security — Password manager & Secrets Manager (cloud API)
  • Let's Encrypt — Free TLS certificates via ACME — health & renewal monitor
  • Step CA — Your own private certificate authority (self-hosted)
  • Vaultwarden — Self-hosted Bitwarden-compatible server (Docker)
Logging & Observability4
  • Dozzle — Live Docker container log viewer
  • Elastic Cloud — Hosted Elasticsearch, Kibana and observability
  • Kibana — ELK's search & dashboard UI (self-hosted)
  • Loki — Grafana's log store — like Prometheus, for logs (self-hosted)

全サービスを見る →

すべてをひとつの Mac アプリで。

FrontierStack は、ローカルでもフリート全体でも、スタック全体のインストール・監視・保護をひとつのネイティブ macOS アプリで行います。

FrontierStack をダウンロード

Apple 公証済み · 安全・安心 · macOS 13 Ventura 以降