Abstract
Apw is an open-source Cybersecurity & Ethical Hacking project. A CLI for Apple Passwords (also known as iCloud Keychain). This project introduces a CLI interface designed to access iCloud passwords and OTP tokens. The core objective is to provide a secure and straightforward way to retrieve iCloud passwords, facilitating integration with other systems or for personal convenience. It is built using TypeScript. The complete source code is publicly available on GitHub under the GNU General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
This project introduces a CLI interface designed to access iCloud passwords and OTP tokens. The core objective is to provide a secure and straightforward way to retrieve iCloud passwords, facilitating integration with other systems or for personal convenience.
It utilises a built in helper tool in macOS 14 and above to facilitate this functionality.
A CLI for access to Apple Passwords. A foundation for enabling integration and automation. Explore the docs » View Demo · Report Bug · Request Feature
2. Objective
A CLI for Apple Passwords (also known as iCloud Keychain)
This project demonstrates how TypeScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Node.js (LTS) and npm / yarn / pnpm
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/bendews/apw.git
cd apw- Ungoogled Chromium: brew install --cask ungoogled-chromium
- or Google Chrome: brew install --cask google-chrome
- or Brave Browser: brew install --cask brave-browser
- or Microsoft Edge: brew install --cask microsoft-edge
brew install bendews/homebrew-tap/apwbrew services start apwapw authOptions:
-h, --help - Show this help.
-V, --version - Show the version number for this program.
Commands:
auth - Authenticate CLI with daemon.
pw - Interactively list or save accounts/passwords.
otp - Interactively list accounts/OTPs.
start - Start the daemon.Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by bendews and published on GitHub under the GNU General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship