Day 5️⃣3️⃣ of #100DaysofYARA: An exploration of how much malware from the @objective_see collection is detected by the XProtect YARA ruleset - I expected it to be higher tbh but this also means there's a lot more macOS malware samples to collect out there so every rule is used 🤔 #GottaDetectThemAll
Script to download some malware, run the XProtect ruleset, and plot the results here: https://gist.github.com/shellcromancer/1192b537e690a1cceee7c057529b9d59 - use it to chart visualize the collection in other ways! To make this work you’ll need to build YARA Python with support for the hash module to use the sha1 function which isn't a default but used heavily in XProtect (see https://github.com/VirusTotal/yara-python/issues/8)
#100DaysofYARA #gottadetectthemall #macos #malware #XProtect
Apple has pushed updates to XProtect and XProtect Remediator
https://eclecticlight.co/2022/11/10/apple-has-pushed-updates-to-xprotect-and-xprotect-remediator-4/
#Technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #Ventura #update #Apple #Macs
#technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #ventura #update #Apple #macs
Everything you need to know about XProtect’s malware protection
https://eclecticlight.co/2022/11/01/everything-you-need-to-know-about-xprotects-malware-protection/
#EndpointSecurity #SilentKnight #Technology #Remediator #XProCheck #security #XProtect #malware #silnite #Macs #MRT
#EndpointSecurity #SilentKnight #technology #Remediator #XProCheck #security #XProtect #malware #silnite #macs #MRT
Silently updated security data files in Ventura
https://eclecticlight.co/2022/10/29/silently-updated-security-data-files-in-ventura/
#Technology #Gatekeeper #security #settings #XProtect #macOS13 #Ventura #update #macOS #Macs #KEXT #SIP #TCC
#technology #Gatekeeper #security #settings #XProtect #macOS13 #ventura #update #macos #macs #KEXT #sip #tcc
Apple has pushed an update to XProtect Remediator
https://eclecticlight.co/2022/10/27/apple-has-pushed-an-update-to-xprotect-remediator-7/
#Technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #Ventura #update #Apple #Macs
#technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #ventura #update #Apple #macs
Last Week on My Mac: It either works or it doesn’t
https://eclecticlight.co/2022/10/16/last-week-on-my-mac-it-either-works-or-it-doesnt/
#ContentCaching #SilentKnight #Technology #Remediator #security #XProtect #silnite #upgrade #update #Macs
#ContentCaching #SilentKnight #technology #Remediator #security #XProtect #silnite #upgrade #update #macs
Apple has pushed updates to XProtect and XProtect Remediator
https://eclecticlight.co/2022/10/13/apple-has-pushed-updates-to-xprotect-and-xprotect-remediator-3/
#Technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #Ventura #update #Apple #Macs
#technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #ventura #update #Apple #macs
XProCheck 1.2 checks macOS malware scans better
https://eclecticlight.co/2022/10/12/xprocheck-1-2-checks-macos-malware-scans-better/
#SilentKnight #Technology #Remediator #XProCheck #security #XProtect #Updates #malware #update #Macs
#SilentKnight #technology #Remediator #XProCheck #security #XProtect #Updates #malware #update #macs
SilentKnight version 2 is designed for Catalina to Ventura
https://eclecticlight.co/2022/10/10/silentknight-version-2-is-designed-for-catalina-to-ventura/
#SilentKnight #Technology #Remediator #security #XProtect #update #Macs
#SilentKnight #technology #Remediator #security #XProtect #update #macs
Last Week on My Mac: Time for a fresh SilentKnight
https://eclecticlight.co/2022/10/09/last-week-on-my-mac-time-for-a-fresh-silentknight/
#SilentKnight #LockRattler #Technology #Gatekeeper #Remediator #security #XProtect #silnite #update #Macs #MRT
#SilentKnight #LockRattler #technology #Gatekeeper #Remediator #security #XProtect #silnite #update #macs #MRT
Apple has pushed an update to XProtect Remediator
https://eclecticlight.co/2022/09/29/apple-has-pushed-an-update-to-xprotect-remediator-6/
#Technology #Remediator #Monterey #security #XProtect #macOS12 #macOS13 #malware #Ventura #update #Apple #Macs
#technology #Remediator #Monterey #security #XProtect #macOS12 #macOS13 #malware #ventura #update #Apple #macs
Where to find Gatekeeper?
https://eclecticlight.co/2022/09/28/where-to-find-gatekeeper/
#translocation #Technology #Gatekeeper #signature #Monterey #security #XProtect #macOS12 #Macs #AMFI
#translocation #technology #Gatekeeper #signature #Monterey #security #XProtect #macOS12 #macs #AMFI
SnowDrift warnings: are they malware?
https://eclecticlight.co/2022/09/19/snowdrift-warnings-are-they-malware/
#CloudMensis #Technology #Remediator #detection #SnowDrift #XProCheck #security #XProtect #malware #Macs #yara #MRT
#cloudmensis #technology #Remediator #detection #snowdrift #XProCheck #security #XProtect #malware #macs #yara #MRT
Interpreting XProCheck’s results and problems
https://eclecticlight.co/2022/09/16/interpreting-xprochecks-results-and-problems/
#Technology #Remediator #XProCheck #security #XProtect #malware #Macs #MRT
#technology #Remediator #XProCheck #security #XProtect #malware #macs #MRT
Apple has pushed an update to XProtect Remediator
https://eclecticlight.co/2022/09/15/apple-has-pushed-an-update-to-xprotect-remediator-5/
#Technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #Ventura #update #Apple #Macs
#technology #Remediator #Monterey #security #XProtect #Updates #macOS12 #macOS13 #malware #ventura #update #Apple #macs
XProCheck 1.1 can now run XProtect Remediator scans on demand
https://eclecticlight.co/2022/09/15/xprocheck-1-1-can-now-run-xprotect-remediator-scans-on-demand/
#Technology #Remediator #XProCheck #security #XProtect #Updates #malware #update #Macs
#technology #Remediator #XProCheck #security #XProtect #Updates #malware #update #macs
How macOS leaves users vulnerable, and unaware of their vulnerability
https://eclecticlight.co/2022/09/13/how-macos-leaves-users-vulnerable-and-unaware-of-their-vulnerability/
#Technology #Remediator #Monterey #security #XProtect #macOS12 #malware #update #Macs
#technology #Remediator #Monterey #security #XProtect #macOS12 #malware #update #macs
Last Week on My Mac: Apple harvest is coming
https://eclecticlight.co/2022/09/11/last-week-on-my-mac-apple-harvest-is-coming/
#Technology #Remediator #security #XProtect #macOS13 #Ventura #update #Apple #crash #Macs #iMac #mini #M2
#technology #Remediator #security #XProtect #macOS13 #ventura #update #Apple #crash #macs #iMac #mini #M2
What shouldn’t you see in your XProCheck results?
https://eclecticlight.co/2022/09/08/what-shouldnt-you-see-in-your-xprocheck-results/
#Technology #Remediator #XProCheck #security #XProtect #malware #Macs #MRT
#technology #Remediator #XProCheck #security #XProtect #malware #macs #MRT