Glossary
XProtect
XProtect is the built-in, signature-based anti-malware technology in macOS, updated by Apple independently of regular OS releases.
XProtect is the anti-malware technology built into macOS. It uses signatures, written in the YARA format, to detect known malware. XProtect checks apps when they are first launched, when they have changed in the file system, and when its signatures are updated. If it finds known malware, macOS blocks it and alerts the user.
Apple updates XProtect signatures separately from full macOS releases, through background security and configuration data updates. That is why the automatic setting to install system data files and security updates should stay enabled on managed Macs. Since macOS Monterey 12.3, the platform also includes XProtect Remediator, which scans on a schedule and can remediate infections it recognizes.
XProtect is a baseline layer, not a full endpoint detection and response product. It targets known, widespread threats and offers limited visibility or alerting to administrators. Organizations with stricter requirements usually add an EDR tool built on the Endpoint Security framework.
Read the Gatekeeper, XProtect and notarization guide for how the layers fit together.