Decoy
com.maccrab.forensics.decoy
Publisher description
Current runtime: this plugin runs unsandboxed with MacCrab's access. Any sandbox wording in the publisher's signed description below reflects an earlier design. The access disclosure on this page describes the current execution path.
Review a selected inert marker registry and supplied MacCrab file-open exports. Exact normalized path and event time can associate a reported open with a marker registered earlier. The result does not establish successful reading, historical inode identity, stable process identity, malicious intent or exfiltration. Imported event authenticity, retention and completeness remain unverified.
The installed collector is read-only and never places, monitors or removes markers automatically. The separate decoy-tools companion explicitly creates a clearly named nonfunctional marker and create-only registry. Cleanup verifies the recorded content and filesystem identity before removal; changed or replaced files are retained. Companion operations refuse overwrite and unsafe paths. A registry does not defend against another process with the same user privileges.
Select registry and event sources in MacCrab 1.22.3. Encrypted results contain selected paths, marker IDs and optional unverified PIDs; commands, environment values and marker bodies are withheld. The plugin does not enable Endpoint Security collection or alter host settings. Arbitrary marker placement may lack event coverage; no reported opens does not mean no access. Missing, malformed and over-limit inputs remain visible gaps. First-party plugins inherit host access; manifest capabilities are declarations, not an independent OS sandbox.
What it reads
Publisher-declared sources for this catalog entry. This list describes intended collection; it does not confine an unsandboxed plugin's file access. The published app's install screen may show older static descriptions rather than the publisher declarations shown here.
registryevents
Access and output privacy
Declared privacy requirements and the current execution path. Output classification describes what the plugin emits; it is separate from the files its process can read.
- Declared macOS access No privacy services listed
- Declared output Content data — requires an encrypted scan
- Runtime Trusted, unsandboxed process. MacCrab validates its Developer ID signature before execution. It inherits the host's privileges, including available Full Disk Access.
- Network The first-party execution path does not enforce an outbound-network block. A publisher's declaration of no network use is a behavior claim.
What it emits
Structured record types this plugin produces. Each row in your case database is one of these.
rave.collectiondecoy.findingdecoy.summary
Community screenshots
Submitted by operators — moderated, and never catalog-authoritative (the signed catalog + sample output are the source of truth).
Discussion
Operator reports, caveats, and notes. Backed by GitHub Discussions on
peterhanily/maccrab-rave-comments; sign in with GitHub to post.
Comments load from giscus.app — if you block third-party scripts, nothing appears here.
Discussion data is hosted by GitHub. The Giscus iframe loads from
giscus.app. Operators with strict third-party-loader
policies should skip this section.
Verification for v0.1.0
Release checks recorded on . These are the catalog's records for this version; this page does not perform a new independent build or collection test.
Source rebuild not applicable: this first-party entry does not publish a source repository for independent rebuilding. You can verify the publisher signature and pinned artifact digests against trusted keys. A recorded maintainer rebuild check does not provide independent source verification.
Recorded release checks
manifest-schema-v1reproducible-build-verifieddeveloper-id-signeded25519-signature-verifiedpublisher-key-pin-matchedpublisher-key-not-revoked
Revocation status comes from the signature-verified revocation list (serial 2), issued . The website checks it during its build; MacCrab checks its own verified list when installing. The issue date does not describe the client's last successful fetch.
No revocation for v0.1.0 is recorded in that list.
Verify the signatures, artifact digests, and revocation list yourself.
Versions
Historical vetting is retained even when a release is revoked. “Current” identifies the version selected by the catalog.
| Version | Tag | Vetted | Revocation status | Reproducibility | Canonical hash |
|---|---|---|---|---|---|
| v0.1.0 current | v0.1.0 | No revocation recorded | Source rebuild not applicable | 2ecd62aae3acc4de… |