macOS Logging and Detection: Unified Log and Endpoint Security
Use the macOS unified log, Endpoint Security, eslogger, sysdiagnose, osquery and Santa to gain visibility and detect suspicious activity on Macs.
~/guides
Des guides de durcissement macOS approfondis et vérifiables pour les administrateurs et équipes sécurité.
Ces guides sont pour l'instant publiés en anglais uniquement. Les traductions sont en préparation.
Use the macOS unified log, Endpoint Security, eslogger, sysdiagnose, osquery and Santa to gain visibility and detect suspicious activity on Macs.
How MDM, Automated Device Enrollment, supervision, configuration profiles and Declarative Device Management fit together to enforce a macOS security baseline.
How to keep macOS patched: softwareupdate CLI, automatic update settings, Background Security Improvements, DDM enforcement, deferrals and third-party apps.
How Gatekeeper, quarantine, code signing, notarization and XProtect decide what runs on a Mac, how to verify them, and how to manage them with MDM and Santa.
What Lockdown Mode restricts on macOS, how to enable it, how it affects MDM, and the companion controls high-risk users need, from ADP to security keys.
What SIP and the Signed System Volume protect on macOS, how to verify them, why they stay on in production, and how system extensions replace kernel extensions.
How FileVault really works on Apple silicon and T2 Macs, how to enable and escrow recovery keys with fdesetup and MDM, and how to lock down startup security.
How to use the NIST macOS Security Compliance Project and CIS Apple macOS Benchmarks to build, tailor, deploy and continuously verify a Mac baseline.
How macOS TCC protects Full Disk Access, Screen Recording, Accessibility and more, and how to audit, reset and manage grants with PPPC profiles.