Mac 서버 보안 및 맬웨어
pf와 애플리케이션 방화벽을 위한 macOS 방화벽 GUI, 침입 방지, 열린 포트 모니터링, 그리고 Mac 서버의 맬웨어를 검사하는 맬웨어 감사.
다층 보안: macOS 애플리케이션 방화벽과 pf, fail2ban/CrowdSec, 알림을 갖춘 열린 포트 감시, SSH 강화, 그리고 맬웨어 감사 패널(Gatekeeper/SIP/FileVault/XProtect, 지속성 메커니즘, ClamAV, YARA, VirusTotal)과 더 깊이 있는 도구(Volatility 3, capa, CAPE/Cuckoo), EDR 플릿 보드까지 제공합니다.
무엇이든 실행되기 전에 물리 키 요구
Fleet 라이선스에서는 앱 잠금에 물리 FIDO2 보안 키를 필수로 지정할 수 있습니다. 암호 잠금 설정 옆에서 Yubico YubiKey, Google Titan 또는 FEITIAN ePass를 등록하면, 등록된 키를 터치할 때까지 FrontierStack은 외부 제어 경로까지 포함해 잠긴 상태로 유지됩니다. 암호도 설정되어 있으면 둘 다 필요합니다. 봉인된 백업 키를 준비해 둘 수 있도록 키를 최대 3개까지 등록할 수 있습니다. 호환되는 USB-C, Lightning, NFC 모델은 Apple 보안 키 시트를 통해 iPhone 및 iPad 앱에서도 동작합니다. 같은 키로 휴대폰 페어링과 권한 상향을 승인하고, 휴대폰이 비밀 값이나 원격 셸을 사용하기 전에 짧은 세션을 열며, AI의 스크립트 비밀 값을 터치 없이는 읽을 수 없도록 암호화할 수 있고, 서버 SSH 접속 시 필수로 지정할 수도 있습니다. 이 경우 한 번의 터치로 열린 세션을 모니터링과 터미널이 함께 사용합니다. 허용하면 앱을 닫은 상태로 작업하는 에이전트도 등록된 키가 꽂혀 있는 동안 읽기 전용 점검을 실행할 수 있으며, 키를 뽑는 즉시 멈춥니다.
네트워킹, 경계 & 통합
Cloudflare(영역, DNS, 캐시, 터널) 및 OPNsense(REST API로 제어)와 긴밀하게 통합되며 — pfSense, OpenWrt, MikroTik RouterOS, UniFi 등도 지원합니다. UPnP 또는 NAT-PMP로 포트를 열고, DDNS로 바뀌는 IP를 따라가고, WireGuard, Tailscale, Headscale, NetBird, Nebula 또는 ZeroTier로 사설 네트워크를 구축하십시오 — 자체 플로 규칙 편집기를 갖춘 셀프 호스팅 ZeroTier 컨트롤러와, 노드 키가 만료되기 전에 경고하는 tailnet 전체 Tailscale 보기도 포함됩니다 — 또한 PoE 스위치 포트(RFC 3621)를 제어해 액세스 포인트나 카메라의 전원을 재투입하고, auth.md로 암호 없는 서비스 로그인을 자동화하십시오. 전체 프로토콜 목록은 보안 레퍼런스를 참조하십시오.
이 용도에 맞춰 설치하거나 모니터링하는 서비스
이 프리셋은 8개 카테고리의 서비스 247개를 보여 줍니다. FrontierStack은 이 작업을 위해 이 서비스들을 설치, 연결 또는 모니터링할 수 있습니다.
Security Tools82
- AbuseIPDB — Crowd-sourced IP reputation / blocklist (cloud API)
- AdGuard — Ad/tracker blocker app + AdGuard DNS & VPN (commercial)
- Admin By Request — Endpoint privilege management / just-in-time admin (agent + API)
- Airlock Digital — Application allowlisting & execution control (agent + API)
- AlienVault OTX — Open Threat Exchange IOC feed (cloud)
- AutoElevate (CyberFOX) — MSP privilege elevation & local-admin control (agent + API)
- BeyondTrust EPM — Endpoint Privilege Management for Mac (agent + API)
- binwalk — Firmware / embedded-file carving & analysis (self-hosted)
- Bitdefender GravityZone — Endpoint protection / EDR (macOS agent + API)
- BlockBlock — Monitor & block persistence in real time (self-hosted)
- Burp Suite — Web app security testing — intercepting proxy & scanner (macOS app)
- capa — Detect capabilities in executables (self-hosted)
- CAPE Sandbox — Malware sandbox w/ config extraction (self-hosted)
- Censys — Internet-wide host & certificate search (cloud API)
- ClamAV — Open-source antivirus engine (self-hosted)
- Cloudbric WAF+ (Penta Security, 펜타시큐리티) — Penta Security cloud WAF, DDoS & bot protection
- Cloudmersive — Virus-scan & content-protection API (cloud / self-host)
- Cortex — Observable analysers & responders engine (self-hosted)
- CrowdSec — Behavioural detection + IP blocking (crowd-sourced)
- CrowdStrike Falcon — Cloud-native EDR/XDR (macOS sensor + API)
- Cuckoo Sandbox — Automated malware-analysis sandbox (self-hosted)
- CyberArk EPM — Endpoint Privilege Manager (agent + API)
- CyberChef — The cyber-Swiss-army-knife for data
- Fail2ban — Bans IPs after suspicious activity (intrusion prevention)
- Fleet — Self-hosted osquery fleet manager (web UI + API)
- Fuzzilli — Coverage-guided JavaScript engine fuzzer (reviewed local binaries)
- Google Safe Browsing — Is your site flagged as malicious by Chrome? (cloud API)
- GreyNoise — Is this IP scanning everyone, or targeting you? (cloud API)
- GRR Rapid Response — Remote live-forensics / IR framework (self-hosted)
- Hands Off! — Per-app network + disk access control (app)
- Huntress — Managed EDR/MDR for SMB & MSPs (agent + API)
- Hybrid Analysis — Malware sandbox (Falcon Sandbox) — API
- Intego NetBarrier — Intego's two-way Mac firewall (NetBarrier X9 / Intego ONE)
- IntelOwl — OSINT / threat-intel analysis platform (self-hosted)
- Jamf Protect — Mac-native endpoint security (agent + API)
- KnockKnock — Reveal persistently installed Mac software (self-hosted)
- Kolide — Device trust & posture (osquery-based agent + API)
- LimaCharlie — API-first SecOps cloud / EDR (agent + API)
- Little Snitch — Commercial network monitor & firewall (macOS app)
- LuLu — Free open-source outbound firewall (macOS app)
- Malwarebytes — Anti-malware (macOS app; business via Nebula API)
- Microsoft Defender for Endpoint — Microsoft EDR for macOS (agent + Graph API)
- MISP — Threat-intelligence sharing platform (self-hosted)
- Mozilla Observatory — Graded HTTP header & TLS scan for your own sites (free API)
- Murus — GUI front-end for the macOS pf firewall (app)
- NetBarrier — Two-way macOS firewall (Intego, app)
- Nuclei — Template-based vulnerability scanner (self-hosted CLI)
- oletools — Analyse malicious Office docs / OLE (self-hosted)
- OpenCTI — Cyber threat-intelligence platform (self-hosted)
- OpenEDR — Open-source endpoint detection & response (self-hosted)
- OpenPhish — Live phishing-URL feed (cloud)
- OpenVAS / Greenbone — Vulnerability scanning (self-hosted)
- OPSWAT MetaDefender — Multi-engine malware scanning & file CDR (self-hosted / API)
- osquery — Query your endpoint like a database (agent)
- OSSEC — Host-based IDS: log, file-integrity & rootkit monitoring
- OWASP ZAP — Open-source web-app security scanner (DAST) — spider, active scan, proxy
- pfBlockerNG — IP & DNS blocklists for pfSense (DNSBL ad/malware blocking)
- Phishing Catcher — Catch phishing domains from CT logs (self-hosted)
- radare2 — Reverse-engineering framework / disassembler (self-hosted)
- Radio Silence — Lightweight macOS outbound firewall (app)
- Santa — macOS binary allowlisting / blocklisting (self-hosted)
- SentinelOne — Autonomous EDR/XDR (macOS agent + API)
- Shodan — Search engine for internet-exposed hosts and services (cloud API)
- Snort — The classic network IDS (self-hosted)
- Sophos Central — Endpoint protection / MDR (macOS agent + API)
- Strix — AI-assisted penetration testing from the local CLI
- Suricata — High-performance IDS/IPS engine (self-hosted)
- TheHive — Security incident-response platform (self-hosted)
- ThreatLocker — Zero Trust app allowlisting & endpoint control (agent + cloud portal)
- URLhaus — Malware-URL feed & lookup API (cloud · abuse.ch)
- urlscan.io — Sandboxed URL scanning — see what a link really does (cloud API)
- Vallum — Per-app outbound firewall & throttle (app)
- Velociraptor — Endpoint visibility & DFIR hunting (self-hosted)
- Vibe Proxy — AI-assisted web security testing & intercepting proxy
- VirusTotal — Multi-engine file/URL reputation (API)
- Volatility 3 — Memory-forensics framework (self-hosted)
- Wireshark — Packet capture and protocol analysis for network diagnosis
- Yakit — Open-source web security testing platform & MITM (macOS app)
- YARA — Pattern-matching engine for malware (self-hosted)
- YARA-X — YARA rewritten in Rust — faster CLI scanner (self-hosted)
- Zeek — Network security monitor / traffic analysis (self-hosted)
- Zenarmor — Next-gen firewall / DPI layer for OPNsense & pfSense (formerly Sensei)
Monitoring49
- Alertmanager — Route and deduplicate Prometheus alerts (self-hosted)
- AppSignal — Application errors, performance, uptime and deploys (SaaS)
- Atatus — APM, logs, infrastructure and real-user monitoring (SaaS)
- Atera — RMM, patching, ticketing and automation (SaaS)
- Beszel — Lightweight server monitoring hub + agents
- Checkmk — Auto-discovering IT monitoring (self-hosted)
- Datadog — Hosted metrics, logs, traces and synthetics (SaaS)
- Dynatrace — Enterprise observability and AIOps platform
- FirstWave NMIS — Open network fault, performance and configuration monitoring
- Glances — Cross-platform system monitor (web/API)
- GoAccess — Real-time access-log analyser (CLI/HTML)
- Grafana — Dashboards for any data source (self-hosted)
- Healthchecks.io — Cron & heartbeat monitoring (cloud or self-hosted)
- Homepage — Self-hosted services dashboard (gethomepage.dev)
- Honeycomb — Observability for high-cardinality events and traces
- Infraon IMS — Unified infrastructure, network and configuration monitoring
- JENNIFER APM (제니퍼, JenniferSoft) — Self-hosted Korean APM (JenniferSoft)
- LibreNMS — Auto-discovering SNMP network monitoring (switches, routers, servers)
- ManageEngine Applications Manager — Application, server, VM and capacity monitoring
- ManageEngine OpManager Nexus — Unified network, server and IT operations management
- Matomo — Full-featured self-hosted web analytics
- N-able N-central — Unified endpoint management, RMM and patching
- Nagios Core — The classic check-based monitor (self-hosted)
- Netdata — Real-time system metrics dashboard
- Netreo — Full-stack infrastructure and business-service observability
- New Relic — Hosted APM, infrastructure and logs (SaaS)
- NinjaOne — Endpoint monitoring, patching and automation (SaaS RMM)
- Node Exporter — Unix host metrics for Prometheus (self-hosted)
- ntopng — Live traffic analysis — who is talking to whom, and how much
- NUT (Network UPS Tools) — Free, open-source UPS monitoring server (upsd)
- Paessler PRTG — Network, server and infrastructure monitoring (Windows or hosted)
- Pandora FMS — Infrastructure, application, log and synthetic monitoring
- PeaNUT — Modern web dashboard for NUT UPS servers
- Plausible — Lightweight, privacy-first analytics
- Prometheus — Time-series metrics & alerting (self-hosted)
- Pulseway — Mobile-first RMM, patching and endpoint automation
- Scouter (open-source APM) — Korean-origin open-source APM
- Scrutiny — S.M.A.R.T. drive health dashboard
- Sentry — Error tracking and performance monitoring
- Server Density — Hosted server, service and container monitoring
- Site24x7 — Infrastructure, application, network and experience monitoring (SaaS)
- Speedtest Tracker — Scheduled internet speed tests + history
- Umami — Simple, privacy-focused analytics (Node)
- Uptime Kuma — Self-hosted uptime monitor
- UptimeRobot — Cloud uptime/SSL monitoring with status pages
- WhaTap (와탭) — Korean SaaS APM, server, Kubernetes & DB monitoring
- Windows Exporter — Windows host metrics for Prometheus (remote)
- Zabbix — Enterprise monitoring — agents, SNMP, triggers (self-hosted)
Policy, Compliance & Governance46
- Amundsen — Open-source data discovery & metadata engine (self-hosted)
- Apache Atlas — Metadata & governance for the Hadoop/data ecosystem (self-hosted)
- Aserto / Topaz — Authorization built on OPA + Zanzibar (self-hosted / cloud)
- AuditBoard — Connected risk, audit & compliance platform (cloud)
- Authzed / SpiceDB — Zanzibar-style permissions database (self-hosted / cloud)
- AWS Config — Native AWS resource configuration & compliance (API)
- AWS Security Hub — Aggregated AWS security findings & standards (API)
- BigID — Data discovery, privacy & governance at scale (cloud)
- Checkov — Static policy scanning for IaC (self-hosted CLI)
- Cloud Custodian — Rules engine for cloud governance & remediation (CLI)
- CloudQuery — Cloud asset inventory as SQL (self-hosted CLI)
- Conftest — Test config files against OPA/Rego policies (CLI)
- DataGrail — Privacy platform — DSR & data mapping automation (cloud)
- DataHub — Open-source metadata platform & data catalogue (self-hosted)
- Drata — Continuous compliance automation & audit readiness (cloud)
- Eramba — Open-source GRC platform (self-hosted)
- Everlaw — Cloud litigation & eDiscovery platform (cloud)
- Google Vault — Retention, legal hold & eDiscovery for Google Workspace (cloud)
- HashiCorp Sentinel — Policy as code for the HashiCorp stack (CLI)
- Hyperproof — Compliance operations & evidence management (cloud)
- immudb — Immutable, cryptographically-verifiable database / audit log (self-hosted)
- Kyverno — Kubernetes-native policy engine, no new language (self-hosted)
- LogicGate Risk Cloud — No-code GRC & risk workflow platform (cloud)
- Logikcull — Self-service eDiscovery & legal hold (cloud, Reveal)
- Microsoft Purview — Data governance, compliance, retention & eDiscovery (cloud)
- MineOS — Data-governance & privacy operations platform (cloud)
- OneTrust — Privacy, GRC & data governance suite (cloud)
- OPA Gatekeeper — OPA policy admission controller for Kubernetes (self-hosted)
- Open Policy Agent (OPA) — General-purpose policy engine, Rego (self-hosted CLI)
- OpenControl — Compliance-as-code documentation toolkit (self-hosted CLI)
- OpenFGA — Open-source fine-grained authorization (Zanzibar-style, self-hosted)
- OpenGRC — Open-source governance, risk & compliance (self-hosted)
- OpenMetadata — Open-source metadata, catalogue & lineage platform (self-hosted)
- Osano — Consent management & privacy compliance (cloud)
- Permify — Open-source fine-grained authorization service (self-hosted)
- Prowler — Open-source multi-cloud security & compliance scanner (CLI)
- Scout Suite — Multi-cloud security-auditing tool (CLI)
- Secureframe — Compliance automation across 40+ frameworks (cloud)
- Securiti — Data privacy, security & governance platform (cloud)
- SimpleRisk — Open-source risk management (self-hosted)
- Smarsh — Communications capture, archiving & supervision (cloud)
- Sprinto — Compliance automation for fast-moving teams (cloud)
- Steampipe — Query cloud APIs with SQL + compliance mods (CLI)
- Thoropass — Compliance + audit in one (formerly Laika, cloud)
- Transcend — Privacy & data-rights automation, incl. AI governance (cloud)
- Vanta — Automated compliance — SOC 2, ISO 27001, HIPAA, GDPR (cloud)
Routers & Firewalls24
- Cisco Secure Firewall — Cisco NGFW (Firepower/ASA) — FMC/FDM API (commercial)
- Citrix NetScaler ADC / Gateway — Application delivery controller & SSL-VPN gateway — NITRO API (commercial)
- Cradlepoint — Cellular/5G edge routers (NCOS + NetCloud)
- F5 BIG-IP — Application delivery controller (LTM/APM) — iControl REST (commercial)
- Firewalla — Home/SMB security router (cloud MSP API)
- FortiGate — Fortinet next-gen firewall — REST API (commercial)
- IPFire — Hardened open-source Linux firewall (web UI)
- Ivanti Connect Secure — SSL-VPN gateway (formerly Pulse Connect Secure) — REST API (commercial)
- MikroTik (RouterOS) — RouterOS devices — REST API (v7+)
- OpenWrt — Open-source router firmware (LuCI / ubus)
- OPNsense — Open-source firewall/router OS (REST API)
- Palo Alto Networks — PAN-OS next-gen firewall — XML/REST API (commercial)
- Peplink — SD-WAN routers with multi-WAN failover/bonding
- pfSense — FreeBSD firewall/router OS (REST via package)
- PoE Switch (RFC 3621) — Managed PoE switch — port power, budget & cycling over SNMP
- Progress Kemp LoadMaster — Load balancer / ADC — APIv2 (commercial)
- SonicWall SMA — Secure Mobile Access SSL-VPN (SMA 100 / SMA 1000) (commercial)
- Sophos Firewall — Next-gen firewall appliance — web UI + API (commercial)
- UFW (Uncomplicated Firewall) — Easy iptables/nftables host firewall for Linux servers (manage over SSH)
- UniFi — Ubiquiti Cloud Gateway / Dream Machine / Superlink + Network controller
- UniFi OS Server — Self-hosted UniFi OS — run the full stack on your own Mac or Linux box
- Untangle / Arista NG Firewall — Debian network gateway — web admin (commercial)
- VyOS — Linux network OS — unified CLI + HTTPS API
- WatchGuard Firebox — Fireware firewall appliance — web UI + Cloud API (commercial)
Secrets Scanning & Supply Chain Security16
- Chainguard — Minimal, low/zero-CVE container images (cloud + chainctl)
- Cosign — Sign & verify container images and artifacts (self-hosted CLI)
- Dependabot — Automated dependency-update & security PRs (GitHub)
- GitGuardian — Secrets detection across code & CI (cloud + ggshield CLI)
- Gitleaks — Open-source secrets scanner for git repos (self-hosted CLI)
- Grype — Fast vulnerability scanner for images & SBOMs (self-hosted CLI)
- Lynis — Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)
- OSV-Scanner — Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)
- Renovate — Automated dependency updates, any platform (self-hosted / app)
- Semgrep Supply Chain — SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)
- Sigstore — Keyless signing ecosystem — Cosign, Fulcio, Rekor (self-hosted / public)
- Snyk — Developer security — code, deps, containers & IaC (cloud + CLI)
- Socket — Proactive dependency / supply-chain attack detection (cloud + CLI)
- Syft — Generate SBOMs from images & filesystems (self-hosted CLI)
- Trivy — Vuln, secret, IaC & SBOM scanner (self-hosted CLI)
- TruffleHog — Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)
Mesh Networking15
- AREDN — Amateur-radio high-speed mesh (ham licence)
- B.A.T.M.A.N.-adv — Layer-2 community Wi-Fi mesh routing (Linux)
- Babel (babeld) — Reliable distance-vector mesh routing protocol
- Briar — P2P messaging over Tor, Wi-Fi & Bluetooth
- cjdns / Hyperboria — Encrypted IPv6 mesh routing (source-routed)
- Meshtastic — LoRa mesh radio for text & location (off-grid)
- Nomad Network (NomadNet) — Resilient comms over Reticulum (pages, files, messaging)
- OLSR (olsrd) — Optimized Link State Routing for MANETs
- qaul — Internet-independent P2P mesh messaging app
- Ratspeak — Private, account-free mesh messaging (Reticulum-based)
- Reticulum — Cryptography-based mesh networking stack (any medium)
- RNode LoRa Devices — Open LoRa radio interface for Reticulum (flash & configure)
- Serval Mesh — Off-grid mesh comms (Serval Project)
- Sideband — LXMF messaging app over Reticulum (desktop/mobile)
- Yggdrasil — Self-arranging encrypted IPv6 mesh (experimental)
Secrets & Vaults11
- 1Password — Password manager with developer secrets API (cloud)
- 1Password SCIM Bridge — Automated 1Password user provisioning (self-hosted bridge)
- Bitwarden — Password manager — cloud or official self-host
- Doppler — Hosted secrets & config manager (cloud)
- GlobalSign — Commercial TLS certificates over ACME (Atlas) — health & renewal monitor
- HashiCorp Vault — Secrets, PKI & dynamic credentials (self-hosted)
- Infisical — Open-source secrets for app configs (cloud or self-hosted)
- Keeper Security — Password manager & Secrets Manager (cloud API)
- Let's Encrypt — Free TLS certificates via ACME — health & renewal monitor
- Step CA — Your own private certificate authority (self-hosted)
- Vaultwarden — Self-hosted Bitwarden-compatible server (Docker)
Logging & Observability4
- Dozzle — Live Docker container log viewer
- Elastic Cloud — Hosted Elasticsearch, Kibana and observability
- Kibana — ELK's search & dashboard UI (self-hosted)
- Loki — Grafana's log store — like Prometheus, for logs (self-hosted)
Mac에서 모두 운영하십시오.
FrontierStack은 이 Mac과 연결된 서버에서 서비스를 설치, 모니터링, 보호하며 — 암호와 키는 어떤 AI에게도 보이지 않게 지킵니다.
FrontierStack 다운로드Apple 공증 완료 · 안전 & 보안 · macOS 13 Ventura 이상
