DEF CON 33 - Mastering Apple Endpoint Security for Advanced macOS Malware Detection - Patrick Wardle

DEF CON 33 - Mastering Apple Endpoint Security for Advanced macOS Malware Detection - Patrick Wardle

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 51:45

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk provides a comprehensive overview of Apple's endpoint security framework, covering both basic concepts and advanced topics for security professionals and malware authors targeting macOS 0:06.

Key Takeaways:
• Endpoint security is Apple's C API for monitoring system events, designed specifically for third-party security tools, making security tool development much easier than before 2:13
• The framework offers over 150 events in two categories: notification events (delivered after something occurs) and authorization events (delivered before something occurs, allowing blocking) 6:44
• Developers must obtain special entitlements from Apple to use endpoint security, and tools require root privileges and full disk access 12:48
• Caching responses for authorization events is crucial for performance but has nuances - it doesn't account for command-line arguments, so binaries like curl or python shouldn't be cached 14:25
• Endpoint security has limitations with script detection - the script member is only set when scripts are executed directly, not when passed as arguments to interpreters 23:02

The talk emphasizes the importance of reading header files rather than online documentation and provides practical examples of implementing endpoint security tools while avoiding common pitfalls 3:32.

Sources:

  • 0:06 Introduction to endpoint security talk
  • 2:13 Definition and purpose of endpoint security
  • 6:44 Event types and categories

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Uhoh and welcome to my talk on mastering Apple's endpoint security. So today we're going to talk about all things related to Apple's endpoint security. We are going to start with some basics but very quickly we will then move into some more advanced topics as well as cover some nuances and pitfalls really shed some light into what I think are the darker corners of endpoint security. Super stoked you're all here. Uh I imagine those of you who are defenders, malware analysts, perhaps those writing security software, the content of this talk, its relevance should be readily apparent. Uh but if you are a attacker, a hacker, a malware author and are targeting Mac OS, cool. You know, it's Defcon. All are welcome. Uh I think this talk will be very relevant to you as well because as we'…