How can you run apps and executable code that hasn’t been notarised? Can you also run those with broken signatures, or none at all? And do the controls actually disable Gatekeeper or XProtect?
Gatekeeper
macOS Sequoia and Tahoe have changed the way Gatekeeper and XProtect are controlled. Can a user disable them, and if so, how? And how can you check whether both are enabled?
How long has it been since XProtect or XProtect Remediator were last updated? Could Apple be changing XProtect to use Apple silicon Macs better? Is there a better defence coming against ClickFix attacks?
By default, quarantine xattrs aren’t attached to new files created by an app. That behaviour is controlled by a setting in their Info.plist, and can be overridden in an Exceptions property list.
How to check secure boot, SIP, Gatekeeper/XProtect, its SSV, FileVault, macOS and its firmware, and XProtect Remediator scans.
Whether a quarantined and notarized app undergoes translocation, Tahoe doesn’t run XProtect checks to determine if it’s malicious. And how to tell when an app is running from translocation.
XProtect, XProtect Remediator, XProtect Behaviour Service, kernel extension excludes, incompatible apps, and some historical remnants, including a database that’s downloaded then vanishes.
Over the last 6 years, XProtect’s Yara rules for detection of malware have increased by a factor of 4, and they now take over 22 times as much space. Here are the numbers and charts.
Stepping through the stages in security checks made on a notarized Mach-O binary command tool, in Ventura 13.4.1 2 years ago, and now in Sequoia 15.4.1.
Why can apps take many seconds or even minutes to launch on some Macs? More results to puzzle and perplex, and a strategy to address the problem.
