macos-internals
macOS operating system internals for detection engineering — process model (XPC, launchd, posix_spawn), TCC (Transparency, Consent, and Control) framework, Gatekeeper and notarisation, code signing enforcement, System Extensions vs kernel extensions, Endpoint Security framework, persistence locations (LaunchAgents, LaunchDaemons, login items), Keychain access, and the mapping between macOS operations and EDR telemetry. Use when authoring detections targeting macOS endpoints.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.