Open-source apps and evidence-first research for macOS and iOS.
hideouts.io · Explore apps · Read research · Project catalog
I’m an independent developer and researcher interested in how Apple systems work: which capabilities software declares in its signature, how devices communicate, what diagnostic artifacts reveal, and where security and privacy boundaries actually sit.
I build tools that turn those questions into practical workflows: inspect a binary, understand a system report, capture device traffic, preserve evidence, or review a change over time. My repositories connect native app development with digital forensics, networking, and research into macOS and iOS internals.
I care about making technical results understandable and keeping their limits visible. A useful finding should tell you what was observed, where it came from, and what still needs investigation.
- iOS Developer Toolkit — My Python workbench for iPhone and iPad diagnostics, developer services, and evidence collection. The Swift edition is a separate native Mac app and CLI with documented device-validation limits.
- System Profiler Explorer — A native interface for understanding what
system_profilerreports, with searchable findings, explanations, and source context. - EntitlementLens — An early-stage workbench for code-signature entitlements, Mach-O evidence, and build-specific RunningBoard policy.
- RVI-Correlator — An experimental investigation companion that brings iPhone packets, Mac process-aware captures, and Unified Logs into a shared timeline.
- macOS Install Security Research — A partial, build-specific investigation of installer provenance, restore components, firmware helpers, and EFI paths.
I use Swift and SwiftUI for native Mac interfaces, Python for device tooling and experiments, Go for scanning, and Shell for focused collection workflows. Platform integrations include Apple device services, Security.framework, Disk Arbitration, and native diagnostic utilities. The website uses Astro and TypeScript to present curated repository content.
Research informs the apps, and the apps make research easier to repeat. Entitlement inspection exposes declared capabilities; network tools preserve packets and their context; diagnostic interfaces help people navigate the underlying evidence.
Across that work, I aim to:
- Keep sources traceable. Preserve timestamps, build identifiers, original artifacts, and hashes where relevant.
- Separate observation from interpretation. Static entitlements describe signed capabilities; timing correlations suggest leads; neither alone establishes runtime behavior or causation.
- Make changes explicit. Distinguish inspection from actions such as installing an app, mounting a volume, disabling an interface, or changing a cloud file.
- Give users control over their data. Favor local analysis, deliberate access permissions, and reviewable exports. Document external services and coverage gaps where a workflow depends on them.
These projects are for developers, researchers, system administrators, and users who want to understand their Macs, iOS devices, and diagnostic evidence.
| Project | What the repository contains | Availability |
|---|---|---|
| MacScope | A Go security-posture and vulnerability scanner, a developing SwiftUI front end, and evidence-preserving reports using macOS state, SOFA, osquery, mSCP, Syft, and Grype. | Source · in development |
| EntitlementLens | A SwiftUI workbench for per-architecture signed entitlements, Mach-O inspection, embedded plist/string evidence, and RunningBoard policy. | Source · early-stage |
| Interface Sentinel | A macOS menu-bar app and privileged LaunchDaemon that enforce a configurable network-interface allowlist, with recovery and uninstall instructions. | Source |
| System Profiler Explorer | A SwiftUI app that organizes system_profiler JSON into searchable findings and explanations; current source also supports snapshots, comparison, and export. |
Published release + source |
| Volume Mount Troubleshooter | A native storage utility for external-volume inspection, APFS/FileVault context, read-only mounting, Disk Arbitration monitoring, and command visibility. | Published release + source |
| Man Page Catalog | A SwiftUI/PDFKit browser and Python generator for local man-page PDFs, with section filters, name/description search, and source paths. | Published release + source |
| DriveTrace | A SwiftUI Google Drive explorer with a local metadata index, compound search, storage views, and Drive Activity evidence; optional broader consent enables file operations. | Source · runnable preview |
These device tools run on a host computer; the native Swift editions are Mac apps. The Python and Swift repositories are separate implementations.
| Project | What the repository contains | Availability |
|---|---|---|
| iOS Developer Toolkit | A Python/PySide6 macOS workbench built around pymobiledevice3: developer images, DVT diagnostics, logs, packet capture, GPX simulation, IPA inspection/installation, backups, and hashed evidence cases. |
Published release + source |
| iOS Developer Toolkit — Swift | A native SwiftUI app and CLI for Apple device and simulator workflows, with readiness checks, guided actions, and evidence manifests. | Published release · physical-device validation partial |
| RVI-Sentinel | Python CLI and optional PySide6 tooling for PCAP/PCAPNG analysis, persistent network baselines, endpoint changes, DNS entropy inspection, and device capture. | Source |
| RVI-Sentinel for macOS | A native SwiftUI edition for guided Remote Virtual Interface capture, capture validation and hashing, network metadata review, and explicitly managed baselines. | Source |
| RVI-Correlator | A SwiftUI companion for RVI, Mac PKTAP, and Unified Log evidence, with clock alignment, source provenance, and transparent uncertainty. Correlation remains experimental. | Source · experimental |
A published release means a GitHub download is available. Downloads may differ from current source; consult each repository for requirements, device coverage, and validation limits.
My research interests span code signing and sandbox policy, networking and service infrastructure, installer and firmware behavior, and the provenance of diagnostic artifacts. These repositories contain specific investigations, evidence collections, and reproducible methods rather than universal verdicts about a system.
| Repository | Focus and contents |
|---|---|
| Apple Infrastructure Research | Analysis of a December 2022 macOS Unified Log snapshot: Apple CDN activity, Private Relay configuration, QUIC, and backend response metadata. |
| iOS System Research | Investigations of sysdiagnose artifacts, carrier Wi-Fi profiles, managed-configuration history, OTA-related records, and iOS behavior, with explicit evidence boundaries. |
| macOS Install Security Research | A partial build-25G83 installer and recovery study: byte comparisons with Apple distributions, RAMDisk analysis, firmware helpers, EFI/NVRAM paths, and bounded finding records. |
| StarSecurity — Software Update RAMDisk | Architectural and forensic analysis of Monterey build 21G115: the T2 restore environment, ramrod, APFS sealed-system-volume construction, and embedded firmware. |
| skywalkctl Field Guide | An unofficial command reference, expanded man page, sanitized examples, and read-only collection scripts grounded in observations on macOS build 25E246. |
| SplunkFound | An ongoing provenance investigation of Splunk-related fields, redacted iOS telemetry diagnostics, and a sandbox-profile fragment, separating artifacts from claims about execution or monitoring. |
| Optical Air-Gap Lab | An offline educational lab for low-contrast QR signaling and synthetic-data reconstruction, including a single-identifier physical-photo result and separate image-based multi-frame tests. |
| Repository | Purpose |
|---|---|
| hideouts.io | The Astro/TypeScript source for my website, with allowlisted README-derived project pages, search, research navigation, and download-verification guidance. |
I want these projects to become more useful together: security and privacy tools that can share context while keeping collection, permissions, and interpretation understandable.
RVI-Correlator already takes a first step by importing captures from RVI-Sentinel and reviewing them alongside Mac packet and log evidence. I want to explore that broader direction through:
- Evidence handoffs between apps: shared, documented formats that preserve timestamps, hashes, source identity, and collection limits.
- Connections between findings: ways to review signed capabilities, system configuration, endpoint activity, and device diagnostics together while keeping each claim tied to its source.
- Privacy-aware collaboration: selective exports, redaction, and explicit user control over what leaves a device or moves between tools.
These are areas I want to investigate and build toward. Each integration needs its own implementation and validation before it can support stronger conclusions.
Visit hideouts.io for app pages, research, and project details. Reproducible bug reports, focused contributions, and evidence-backed research corrections are welcome through the contribution guide.
For security reports, use the disclosure guidance.




