To detect new Mac malware, a behavior-based approach is needed. This session will discuss our open-source monitoring framework which passively collects system events, and will then detail our rule-based system that leverages Apple’s game engine to quickly and efficiently apply rules against these collected events. End result? A comprehensive, extensible detection, response and threat hunting platform.
Learning Objectives: 1: Understand current threats facing macOS. 2: Learn about monitoring and audit capabilities of macOS. 3: Understand how Apple’s built-in game engine can be used to detect cyberthreats.