Mac server security & malware
Firewall, intrusion prevention, open-ports monitoring and a full Malware Audit; for Macs and the fleet.
Layered security: the macOS Application Firewall and pf, fail2ban/CrowdSec, an open-ports watch with alerts, SSH hardening, and a Malware Audit pane (Gatekeeper/SIP/FileVault/XProtect, persistence, ClamAV, YARA, VirusTotal) with deeper tooling (Volatility 3, capa, CAPE/Cuckoo) and an EDR Fleet board.
Require a physical key before anything runs
With a Fleet licence, App Lock can require a physical FIDO2 security key. Enrol a Yubico YubiKey, Google Titan or FEITIAN ePass beside the password-lock setting and FrontierStack stays locked; including its external control surfaces; until you touch an enrolled key. If a password is also configured, both are required. You can register up to three keys so a sealed backup is ready. Compatible USB-C, Lightning and NFC models work through Apple's security-key sheet in the iPhone and iPad app too.
Networking, perimeter & integrations
Tight integrations with Cloudflare (zones, DNS, cache, tunnels) and OPNsense (driven by its REST API); plus pfSense, OpenWrt, MikroTik RouterOS, UniFi and more. Open a port with UPnP or NAT-PMP, follow a changing IP with DDNS, build a private network with WireGuard, Tailscale, Headscale, NetBird, Nebula or ZeroTier; including a self-hosted ZeroTier controller with its own flow-rule editor, and a tailnet-wide Tailscale view that warns before node keys expire; control PoE switch ports (RFC 3621) to power-cycle an access point or camera, and automate password-free service logins with auth.md. See the security reference for the full protocol list.
Services we install or monitor for this
This preset shows 237 services in 8 categories. FrontierStack can install, connect or monitor them for this job.
Security Tools81
- AbuseIPDB; Crowd-sourced IP reputation / blocklist (cloud API)
- AdGuard; Ad/tracker blocker app + AdGuard DNS & VPN (commercial)
- Admin By Request; Endpoint privilege management / just-in-time admin (agent + API)
- Airlock Digital; Application allowlisting & execution control (agent + API)
- AlienVault OTX; Open Threat Exchange IOC feed (cloud)
- AutoElevate (CyberFOX); MSP privilege elevation & local-admin control (agent + API)
- BeyondTrust EPM; Endpoint Privilege Management for Mac (agent + API)
- binwalk; Firmware / embedded-file carving & analysis (self-hosted)
- Bitdefender GravityZone; Endpoint protection / EDR (macOS agent + API)
- BlockBlock; Monitor & block persistence in real time (self-hosted)
- Burp Suite; Web app security testing; intercepting proxy & scanner (macOS app)
- capa; Detect capabilities in executables (self-hosted)
- CAPE Sandbox; Malware sandbox w/ config extraction (self-hosted)
- Censys; Internet-wide host & certificate search (cloud API)
- ClamAV; Open-source antivirus engine (self-hosted)
- Cloudmersive; Virus-scan & content-protection API (cloud / self-host)
- Cortex; Observable analysers & responders engine (self-hosted)
- CrowdSec; Behavioural detection + IP blocking (crowd-sourced)
- CrowdStrike Falcon; Cloud-native EDR/XDR (macOS sensor + API)
- Cuckoo Sandbox; Automated malware-analysis sandbox (self-hosted)
- CyberArk EPM; Endpoint Privilege Manager (agent + API)
- CyberChef; The cyber-Swiss-army-knife for data
- Fail2ban; Bans IPs after suspicious activity (intrusion prevention)
- Fleet; Self-hosted osquery fleet manager (web UI + API)
- Fuzzilli; Coverage-guided JavaScript engine fuzzer (reviewed local binaries)
- Google Safe Browsing; Is your site flagged as malicious by Chrome? (cloud API)
- GreyNoise; Is this IP scanning everyone, or targeting you? (cloud API)
- GRR Rapid Response; Remote live-forensics / IR framework (self-hosted)
- Hands Off!; Per-app network + disk access control (app)
- Huntress; Managed EDR/MDR for SMB & MSPs (agent + API)
- Hybrid Analysis; Malware sandbox (Falcon Sandbox); API
- Intego NetBarrier; Intego's two-way Mac firewall (NetBarrier X9 / Intego ONE)
- IntelOwl; OSINT / threat-intel analysis platform (self-hosted)
- Jamf Protect; Mac-native endpoint security (agent + API)
- KnockKnock; Reveal persistently installed Mac software (self-hosted)
- Kolide; Device trust & posture (osquery-based agent + API)
- LimaCharlie; API-first SecOps cloud / EDR (agent + API)
- Little Snitch; Commercial network monitor & firewall (macOS app)
- LuLu; Free open-source outbound firewall (macOS app)
- Malwarebytes; Anti-malware (macOS app; business via Nebula API)
- Microsoft Defender for Endpoint; Microsoft EDR for macOS (agent + Graph API)
- MISP; Threat-intelligence sharing platform (self-hosted)
- Mozilla Observatory; Graded HTTP header & TLS scan for your own sites (free API)
- Murus; GUI front-end for the macOS pf firewall (app)
- NetBarrier; Two-way macOS firewall (Intego, app)
- Nuclei; Template-based vulnerability scanner (self-hosted CLI)
- oletools; Analyse malicious Office docs / OLE (self-hosted)
- OpenCTI; Cyber threat-intelligence platform (self-hosted)
- OpenEDR; Open-source endpoint detection & response (self-hosted)
- OpenPhish; Live phishing-URL feed (cloud)
- OpenVAS / Greenbone; Vulnerability scanning (self-hosted)
- OPSWAT MetaDefender; Multi-engine malware scanning & file CDR (self-hosted / API)
- osquery; Query your endpoint like a database (agent)
- OSSEC; Host-based IDS: log, file-integrity & rootkit monitoring
- OWASP ZAP; Open-source web-app security scanner (DAST); spider, active scan, proxy
- pfBlockerNG; IP & DNS blocklists for pfSense (DNSBL ad/malware blocking)
- Phishing Catcher; Catch phishing domains from CT logs (self-hosted)
- radare2; Reverse-engineering framework / disassembler (self-hosted)
- Radio Silence; Lightweight macOS outbound firewall (app)
- Santa; macOS binary allowlisting / blocklisting (self-hosted)
- SentinelOne; Autonomous EDR/XDR (macOS agent + API)
- Shodan; Search engine for internet-exposed hosts and services (cloud API)
- Snort; The classic network IDS (self-hosted)
- Sophos Central; Endpoint protection / MDR (macOS agent + API)
- Strix; AI-assisted penetration testing from the local CLI
- Suricata; High-performance IDS/IPS engine (self-hosted)
- TheHive; Security incident-response platform (self-hosted)
- ThreatLocker; Zero Trust app allowlisting & endpoint control (agent + cloud portal)
- URLhaus; Malware-URL feed & lookup API (cloud · abuse.ch)
- urlscan.io; Sandboxed URL scanning; see what a link really does (cloud API)
- Vallum; Per-app outbound firewall & throttle (app)
- Velociraptor; Endpoint visibility & DFIR hunting (self-hosted)
- Vibe Proxy; AI-assisted web security testing & intercepting proxy
- VirusTotal; Multi-engine file/URL reputation (API)
- Volatility 3; Memory-forensics framework (self-hosted)
- Wireshark; Packet capture and protocol analysis for network diagnosis
- Yakit; Open-source web security testing platform & MITM (macOS app)
- YARA; Pattern-matching engine for malware (self-hosted)
- YARA-X; YARA rewritten in Rust; faster CLI scanner (self-hosted)
- Zeek; Network security monitor / traffic analysis (self-hosted)
- Zenarmor; Next-gen firewall / DPI layer for OPNsense & pfSense (formerly Sensei)
Policy, Compliance & Governance46
- Amundsen; Open-source data discovery & metadata engine (self-hosted)
- Apache Atlas; Metadata & governance for the Hadoop/data ecosystem (self-hosted)
- Aserto / Topaz; Authorization built on OPA + Zanzibar (self-hosted / cloud)
- AuditBoard; Connected risk, audit & compliance platform (cloud)
- Authzed / SpiceDB; Zanzibar-style permissions database (self-hosted / cloud)
- AWS Config; Native AWS resource configuration & compliance (API)
- AWS Security Hub; Aggregated AWS security findings & standards (API)
- BigID; Data discovery, privacy & governance at scale (cloud)
- Checkov; Static policy scanning for IaC (self-hosted CLI)
- Cloud Custodian; Rules engine for cloud governance & remediation (CLI)
- CloudQuery; Cloud asset inventory as SQL (self-hosted CLI)
- Conftest; Test config files against OPA/Rego policies (CLI)
- DataGrail; Privacy platform; DSR & data mapping automation (cloud)
- DataHub; Open-source metadata platform & data catalogue (self-hosted)
- Drata; Continuous compliance automation & audit readiness (cloud)
- Eramba; Open-source GRC platform (self-hosted)
- Everlaw; Cloud litigation & eDiscovery platform (cloud)
- Google Vault; Retention, legal hold & eDiscovery for Google Workspace (cloud)
- HashiCorp Sentinel; Policy as code for the HashiCorp stack (CLI)
- Hyperproof; Compliance operations & evidence management (cloud)
- immudb; Immutable, cryptographically-verifiable database / audit log (self-hosted)
- Kyverno; Kubernetes-native policy engine, no new language (self-hosted)
- LogicGate Risk Cloud; No-code GRC & risk workflow platform (cloud)
- Logikcull; Self-service eDiscovery & legal hold (cloud, Reveal)
- Microsoft Purview; Data governance, compliance, retention & eDiscovery (cloud)
- MineOS; Data-governance & privacy operations platform (cloud)
- OneTrust; Privacy, GRC & data governance suite (cloud)
- OPA Gatekeeper; OPA policy admission controller for Kubernetes (self-hosted)
- Open Policy Agent (OPA); General-purpose policy engine, Rego (self-hosted CLI)
- OpenControl; Compliance-as-code documentation toolkit (self-hosted CLI)
- OpenFGA; Open-source fine-grained authorization (Zanzibar-style, self-hosted)
- OpenGRC; Open-source governance, risk & compliance (self-hosted)
- OpenMetadata; Open-source metadata, catalogue & lineage platform (self-hosted)
- Osano; Consent management & privacy compliance (cloud)
- Permify; Open-source fine-grained authorization service (self-hosted)
- Prowler; Open-source multi-cloud security & compliance scanner (CLI)
- Scout Suite; Multi-cloud security-auditing tool (CLI)
- Secureframe; Compliance automation across 40+ frameworks (cloud)
- Securiti; Data privacy, security & governance platform (cloud)
- SimpleRisk; Open-source risk management (self-hosted)
- Smarsh; Communications capture, archiving & supervision (cloud)
- Sprinto; Compliance automation for fast-moving teams (cloud)
- Steampipe; Query cloud APIs with SQL + compliance mods (CLI)
- Thoropass; Compliance + audit in one (formerly Laika, cloud)
- Transcend; Privacy & data-rights automation, incl. AI governance (cloud)
- Vanta; Automated compliance; SOC 2, ISO 27001, HIPAA, GDPR (cloud)
Monitoring46
- Alertmanager; Route and deduplicate Prometheus alerts (self-hosted)
- AppSignal; Application errors, performance, uptime and deploys (SaaS)
- Atatus; APM, logs, infrastructure and real-user monitoring (SaaS)
- Atera; RMM, patching, ticketing and automation (SaaS)
- Beszel; Lightweight server monitoring hub + agents
- Checkmk; Auto-discovering IT monitoring (self-hosted)
- Datadog; Hosted metrics, logs, traces and synthetics (SaaS)
- Dynatrace; Enterprise observability and AIOps platform
- FirstWave NMIS; Open network fault, performance and configuration monitoring
- Glances; Cross-platform system monitor (web/API)
- GoAccess; Real-time access-log analyser (CLI/HTML)
- Grafana; Dashboards for any data source (self-hosted)
- Healthchecks.io; Cron & heartbeat monitoring (cloud or self-hosted)
- Homepage; Self-hosted services dashboard (gethomepage.dev)
- Honeycomb; Observability for high-cardinality events and traces
- Infraon IMS; Unified infrastructure, network and configuration monitoring
- LibreNMS; Auto-discovering SNMP network monitoring (switches, routers, servers)
- ManageEngine Applications Manager; Application, server, VM and capacity monitoring
- ManageEngine OpManager Nexus; Unified network, server and IT operations management
- Matomo; Full-featured self-hosted web analytics
- N-able N-central; Unified endpoint management, RMM and patching
- Nagios Core; The classic check-based monitor (self-hosted)
- Netdata; Real-time system metrics dashboard
- Netreo; Full-stack infrastructure and business-service observability
- New Relic; Hosted APM, infrastructure and logs (SaaS)
- NinjaOne; Endpoint monitoring, patching and automation (SaaS RMM)
- Node Exporter; Unix host metrics for Prometheus (self-hosted)
- ntopng; Live traffic analysis; who is talking to whom, and how much
- NUT (Network UPS Tools); UPS monitoring server (upsd) for many devices
- Paessler PRTG; Network, server and infrastructure monitoring (Windows or hosted)
- Pandora FMS; Infrastructure, application, log and synthetic monitoring
- PeaNUT; Modern web dashboard for NUT UPS servers
- Plausible; Lightweight, privacy-first analytics
- Prometheus; Time-series metrics & alerting (self-hosted)
- Pulseway; Mobile-first RMM, patching and endpoint automation
- Scrutiny; S.M.A.R.T. drive health dashboard
- Sentry; Error tracking and performance monitoring
- Server Density; Hosted server, service and container monitoring
- Site24x7; Infrastructure, application, network and experience monitoring (SaaS)
- Speedtest Tracker; Scheduled internet speed tests + history
- Umami; Simple, privacy-focused analytics (Node)
- Uptime Kuma; Self-hosted uptime monitor
- UptimeRobot; Cloud uptime/SSL monitoring with status pages
- Windows Exporter; Windows host metrics for Prometheus (remote)
- Zabbix; Enterprise monitoring; agents, SNMP, triggers (self-hosted)
Routers & Firewalls19
- Cisco Secure Firewall; Cisco NGFW (Firepower/ASA); FMC/FDM API (commercial)
- Cradlepoint; Cellular/5G edge routers (NCOS + NetCloud)
- Firewalla; Home/SMB security router (cloud MSP API)
- FortiGate; Fortinet next-gen firewall; REST API (commercial)
- IPFire; Hardened open-source Linux firewall (web UI)
- MikroTik (RouterOS); RouterOS devices; REST API (v7+)
- OpenWrt; Open-source router firmware (LuCI / ubus)
- OPNsense; Open-source firewall/router OS (REST API)
- Palo Alto Networks; PAN-OS next-gen firewall; XML/REST API (commercial)
- Peplink; SD-WAN routers with multi-WAN failover/bonding
- pfSense; FreeBSD firewall/router OS (REST via package)
- PoE Switch (RFC 3621); Managed PoE switch; port power, budget & cycling over SNMP
- Sophos Firewall; Next-gen firewall appliance; web UI + API (commercial)
- UFW (Uncomplicated Firewall); Easy iptables/nftables host firewall for Linux servers (manage over SSH)
- UniFi; Ubiquiti Cloud Gateway / Dream Machine / Superlink + Network controller
- UniFi OS Server; Self-hosted UniFi OS; run the full stack on your own Mac or Linux box
- Untangle / Arista NG Firewall; Debian network gateway; web admin (commercial)
- VyOS; Linux network OS; unified CLI + HTTPS API
- WatchGuard Firebox; Fireware firewall appliance; web UI + Cloud API (commercial)
Secrets Scanning & Supply Chain Security16
- Chainguard; Minimal, low/zero-CVE container images (cloud + chainctl)
- Cosign; Sign & verify container images and artifacts (self-hosted CLI)
- Dependabot; Automated dependency-update & security PRs (GitHub)
- GitGuardian; Secrets detection across code & CI (cloud + ggshield CLI)
- Gitleaks; Open-source secrets scanner for git repos (self-hosted CLI)
- Grype; Fast vulnerability scanner for images & SBOMs (self-hosted CLI)
- Lynis; Host security auditing & hardening for Unix/Linux/macOS (self-hosted CLI)
- OSV-Scanner; Dependency vulnerability scanner backed by OSV.dev (self-hosted CLI)
- Renovate; Automated dependency updates, any platform (self-hosted / app)
- Semgrep Supply Chain; SAST + reachable-dependency (SCA) scanning (self-hosted CLI / cloud)
- Sigstore; Keyless signing ecosystem; Cosign, Fulcio, Rekor (self-hosted / public)
- Snyk; Developer security; code, deps, containers & IaC (cloud + CLI)
- Socket; Proactive dependency / supply-chain attack detection (cloud + CLI)
- Syft; Generate SBOMs from images & filesystems (self-hosted CLI)
- Trivy; Vuln, secret, IaC & SBOM scanner (self-hosted CLI)
- TruffleHog; Find & VERIFY leaked secrets across code, git history, cloud & CI (self-hosted CLI)
Mesh Networking15
- AREDN; Amateur-radio high-speed mesh (ham licence)
- B.A.T.M.A.N.-adv; Layer-2 community Wi-Fi mesh routing (Linux)
- Babel (babeld); Reliable distance-vector mesh routing protocol
- Briar; P2P messaging over Tor, Wi-Fi & Bluetooth
- cjdns / Hyperboria; Encrypted IPv6 mesh routing (source-routed)
- Meshtastic; LoRa mesh radio for text & location (off-grid)
- Nomad Network (NomadNet); Resilient comms over Reticulum (pages, files, messaging)
- OLSR (olsrd); Optimized Link State Routing for MANETs
- qaul; Internet-independent P2P mesh messaging app
- Ratspeak; Private, account-free mesh messaging (Reticulum-based)
- Reticulum; Cryptography-based mesh networking stack (any medium)
- RNode LoRa Devices; Open LoRa radio interface for Reticulum (flash & configure)
- Serval Mesh; Off-grid mesh comms (Serval Project)
- Sideband; LXMF messaging app over Reticulum (desktop/mobile)
- Yggdrasil; Self-arranging encrypted IPv6 mesh (experimental)
Secrets & Vaults10
- 1Password; Password manager with developer secrets API (cloud)
- 1Password SCIM Bridge; Automated 1Password user provisioning (self-hosted bridge)
- Bitwarden; Password manager; cloud or official self-host
- Doppler; Hosted secrets & config manager (cloud)
- HashiCorp Vault; Secrets, PKI & dynamic credentials (self-hosted)
- Infisical; Open-source secrets for app configs (cloud or self-hosted)
- Keeper Security; Password manager & Secrets Manager (cloud API)
- Let's Encrypt; Free TLS certificates via ACME; health & renewal monitor
- Step CA; Your own private certificate authority (self-hosted)
- Vaultwarden; Self-hosted Bitwarden-compatible server (Docker)
Logging & Observability4
- Dozzle; Live Docker container log viewer
- Elastic Cloud; Hosted Elasticsearch, Kibana and observability
- Kibana; ELK's search & dashboard UI (self-hosted)
- Loki; Grafana's log store; like Prometheus, for logs (self-hosted)
Run it from your Mac.
FrontierStack installs, monitors and secures services on this Mac and on linked servers.
Download FrontierStack