Sadly no new ES events for macOS 26. There are a few nice event property updates and additions to the process structure though :)
Sadly no new ES events for macOS 26. There are a few nice event property updates and additions to the process structure though :)
Thank you! Cupertino is hoppin' π
#WWDC25 π₯³
Next up is by intercepting the client's call to es_subscribe itself:
- Script: gist.github.com/Brandon7CC/e...
- Documentation: github.com/redcanaryco/...
First up, and recommended, is by hooking the client's CoreAnalytics sendEvent function:
- Script: gist.github.com/Brandon7CC/1...
- Documentation: github.com/redcanaryco/...
Wanted to re-share some work from Dec 2023 looking at ES internals w/Frida.
I documented in-detail two variations here to pull event subscriptions w/this method. If you have a go -- let me know! π§΅
I'm going to WWDC this year!! A childhood dream is coming true! π#WWDC25
Wow, time flies! Mac Monitor turns two next month π₯³
What began as a passion project of mine has been adopted more widely than I could have imagined.
A huge thank you to all those who supported the project along the way! What are some of your favorite use cases? What do you want to see be added? πββοΈ
The other day I was updating one of my favorite Core Data projectsβ¦. π and came across this blog that would have saved me a lot of time. alexj.org/11/core-data...
You canβt prefix a property with βnew*β because of allocation nuances between ARC and the Core Data stack!
Today Red Canary dropped their 2025 threat detection report! Loved the Mac section
redcanary.com/threat-detec...
A fun yearly endeavor for me is contributing to the Red Canary Threat Detection Report, and the 2025 edition is out today! distilled into one report!
Get your free copy of our 2025 Threat Detection Report now. β¬οΈ
#ThreatReport #SecOps #ThreatIntel
redcanary.com/threat-detec...
The team found some new XCSSET behaviors to further infect additional Xcode projects / maintain persistence!
www.microsoft.com/en-us/securi...
Today we released a new version of the macOS Security Compliance Project (mSCP). All the published Apple Intelligence controls for macOS/iOS/iPadOS included. Also, DISA STIG v1r1 for macOS Sequoia and BSI indigo for iOS/iPadOS 18. #mscp #macOS #ios #compliance
π£Iβm happy to announce that Iβm planning to write a brand new βmacOS Vulnerability Researchβ training. π₯³
Considering the amount of work the writing requires it will be available late 2025 or early 2026. It will be Live class only, and likely only once or twice a year.
Shout-out to the incredible Huntress crew for the special T-shirt ποΈ and a killer #OBTS presentation by @stuartjash.bsky.social and @re.wtf!
Extremely excited to be giving a talk titled "Mac, Wheres My Bootstrap" tomorrow at #OBTS with @theevilbit.bsky.social! Join us live on YouTube or in-person at 2:40pm HST / 7:40pm EST. We'll be dropping a tool you can walk away with :)
All the recordings from #r2con2024. π€© π
radare.org/con/2024/