macOS Logging and Detection: Unified Log and Endpoint Security
Use the macOS unified log, Endpoint Security, eslogger, sysdiagnose, osquery and Santa to gain visibility and detect suspicious activity on Macs.
macOS 15 Sequoia · macOS 26 Tahoe · Apple silicon
A practical map of macOS security controls — from FileVault and System Integrity Protection to TCC, MDM profiles and NIST mSCP baselines — with the commands to apply and verify each one.
$ fdesetup status
FileVault is On.
$ csrutil status
System Integrity Protection status: enabled.
$ spctl --status
assessments enabled
$ socketfilterfw --getglobalstate
Firewall is enabled. (State = 1)
$ profiles status -type enrollment
MDM enrollment: Yes (User Approved)
defense-in-depth
macOS security is a stack of cooperating layers. Hardening means confirming each one is on, enforced and monitored.
The Secure Enclave, the boot ROM and Startup Security policy decide what code may run before macOS loads.
SIP and the Signed System Volume keep the OS read-only and verifiable, even against root.
Gatekeeper, notarization, XProtect and TCC gate what runs and what it can touch.
MDM profiles enforce the baseline; unified logs and Endpoint Security tell you when it drifts.
/Library/Hardening
Eleven areas, from the boot chain to the people most likely to be targeted. Each one links to guides with configuration, verification commands and pitfalls.
FileVault, recovery-key escrow, Startup Security and Activation Lock.
System Integrity Protection, the sealed system volume and kernel extensions.
Gatekeeper, code signing, notarization, XProtect and binary allowlisting.
Application Firewall, stealth mode, pf rules, sharing services and encrypted DNS.
Standard users by default, scoped sudo, password policy and screen lock.
Transparency, Consent and Control: Full Disk Access, screen recording and PPPC profiles.
softwareupdate, automatic security responses and DDM update enforcement.
Automated enrollment, supervision, .mobileconfig payloads and declarative management.
Unified Logging predicates, the Endpoint Security framework and EDR deployment.
NIST mSCP baselines, CIS macOS Benchmarks, tailoring and continuous compliance.
Lockdown Mode, Advanced Data Protection and security keys for targeted people.
Short, accurate definitions of the Apple platform security terms used across the guides.
~/guides
Use the macOS unified log, Endpoint Security, eslogger, sysdiagnose, osquery and Santa to gain visibility and detect suspicious activity on Macs.
How MDM, Automated Device Enrollment, supervision, configuration profiles and Declarative Device Management fit together to enforce a macOS security baseline.
How to keep macOS patched: softwareupdate CLI, automatic update settings, Background Security Improvements, DDM enforcement, deferrals and third-party apps.
How Gatekeeper, quarantine, code signing, notarization and XProtect decide what runs on a Mac, how to verify them, and how to manage them with MDM and Santa.
What Lockdown Mode restricts on macOS, how to enable it, how it affects MDM, and the companion controls high-risk users need, from ADP to security keys.
What SIP and the Signed System Volume protect on macOS, how to verify them, why they stay on in production, and how system extensions replace kernel extensions.
Every control comes with the command that proves its current state, so you can audit a Mac instead of trusting a checkbox.
Where a setting can be managed, we show the configuration profile or MDM approach alongside the local command.
Controls are explained in the context of the CIS macOS Benchmarks and the NIST macOS Security Compliance Project.