← Back to blog

Tuoni 0.15.0: macOS agents have arrived

Tuoni 0.15.0 brings macOS agents to Intel and Apple Silicon, with familiar listeners, commands, and plugin-driven operations.

Tuoni 0.15.0 is here, and macOS is now part of the Tuoni agent family. Commercial users can generate macOS agents, bring them back through established listener workflows, and operate them from the same interface and API used across the rest of a Tuoni environment.

This is a significant expansion for teams whose estates no longer fit inside a Windows-only picture. Developer fleets, executive devices, security teams, and production environments increasingly include Macs. Tuoni can now bring those systems into a single, consistent command-and-control workflow for red-team, purple-team, and defence exercises.

Intel and Apple Silicon

The new agent ships as architecture-specific Mach-O executables for Intel x86-64 and Apple Silicon arm64. On Apple Silicon, the arm64 build runs natively without relying on Rosetta to translate an Intel binary. Operators choose the template that matches the target when generating the payload.

Both architectures report macOS identity and architecture information back to Tuoni alongside the session metadata operators expect: user, process, PID, working directory, hostname, network addresses, and privilege context. That makes a newly connected Mac immediately recognizable and ready for triage.

From payload to active agent

The operator flow stays deliberately familiar:

  1. Select the macOS payload template and choose Intel x86-64 or Apple Silicon arm64.
  2. Choose one compatible listener for the generated payload.
  3. Configure the payload and listener options for the operation.
  4. Generate the native executable and deploy it.
  5. Manage the returning agent through Tuoni's normal session, command, result, and automation flows.

Payload settings include practical controls such as an initial wait, plugin-loading directory, mutex, auto-destruct date, padding, and support for a custom template. The plugin-driven design exposes the same workflow through Tuoni's existing payload APIs, so teams can automate generation without learning a separate Mac-specific interface.

Tuoni 0.15.0 provides multiple confirmed connection choices for both Mac architectures: HTTP or HTTPS, DNS, reverse TCP, relay reverse TCP, and relay TCP bind. Teams can select the transport that matches their lab, exercise, or engagement design instead of being pushed into one Mac-specific channel.

Useful capability from day one

The first macOS release is already equipped for practical endpoint work. Operators can inspect host and process information, execute shell commands, navigate directories, and perform common file operations. Plugin-backed commands extend that foundation with capabilities such as screenshots, port scanning, SOCKS and reverse port forwarding.

These are representative examples rather than a promise that every command on every Tuoni platform is identical. Compatibility is negotiated against the connected agent, so the interface can expose the operations and execution format that the macOS session actually supports.

Mach-O plugins, the Tuoni way

macOS support builds on the execution model introduced in Tuoni 0.14. Compatible plugin commands are delivered as native Mach-O libraries and run in the agent's self-process execution context. This keeps the core agent focused while letting Tuoni deliver the code required for a specific task. When configured, the agent also participates in Tuoni's encrypted communications flow.

That foundation gives macOS useful coverage now and a direct path for more commands to follow. Tuoni can match the selected x86-64 or arm64 implementation to the connected agent while preserving the same plugin boundaries used on other platforms.

One workflow for a mixed estate

The real value of this release is not a platform checkbox. It is the ability to work across Windows, Linux, BSD, Intel Macs, and Apple Silicon Macs without creating a separate operating model for each one. Tuoni keeps payload generation, listener configuration, agent metadata, commands, results, and automation in one place.

Tuoni 0.15.0 establishes the native foundation for macOS and makes it available to Commercial users now. We are excited to see how teams use it in mixed-platform assessments, detection validation, and large cyber defence exercises—and where the Mac agent should go next.

Ready to bring Intel and Apple Silicon Macs into your Tuoni operations?

Access commercial downloads Request a licence or demo