Skip to content

The Eclectic Light Company

Macs & painting – 🦉 No AI content
Main navigation
  • Downloads
  • Freeware
  • M-series Macs
  • Mac Problems
  • Mac articles
  • Macs
  • Art

yara

Explainer: Yara rules

Used by two of XProtect’s malware detection features, Yara rules are valuable way to check whether files satisfy a logical condition, and more.

August 20, 2025 Macs, Technology

How XProtect’s detection rules have changed 2019-25

Over the last 6 years, XProtect’s Yara rules for detection of malware have increased by a factor of 4, and they now take over 22 times as much space. Here are the numbers and charts.

August 15, 2025 Macs, Technology

Why XProtect Remediator scans now take longer

Scans used to take just a few minutes, but even on a fast M4 Pro now usually take more than half an hour. What is XProtect Remediator up to?

January 3, 2025 Macs, Technology

Is there more XProtection in Sequoia?

In Sequoia, XProtect’s data is now updated in a different way. Does this change its capabilities, though? A quick dip into YARA files has the answer.

October 4, 2024 Macs, Technology

What malware can macOS remove?

T T Read More

Until two years ago, Apple’s Malware Removal Tool, MRT, was all that macOS had to deal with any […]

March 9, 2024 Macs, Technology

Why have there been so many XProtect updates?

In the first 6 weeks of this year, Apple has released 5 updates to XProtect containing 11 completely new detection rules for malware. Why?

February 10, 2024 Macs, Technology

SnowDrift warnings: are they malware?

Two readers reported odd warnings when checking macOS malware scans. Are they significant, or errors? And what are the differences between XProtect and XProtect.app?

September 19, 2022 Macs, Technology

XProtect: What do we know about it?

Where to find its data files, what each contains and does, when XProtect is called to scan software, and a list of known malware it should detect.

October 27, 2020 Macs, Technology

How has XProtect changed?

Apple’s pushed update to XProtect’s data a couple of days ago is one of the most substantial since […]

October 3, 2019 Macs, Technology
Blog at WordPress.com.
Footer navigation
  • Free Software Menu
  • About & Contact
  • Macs
  • Painting
  • Downloads
  • Mac problem-solving
  • Extended attributes (xattrs)
  • Painting topics
  • SilentKnight, Skint, SystHist, silnite, LockRattler & Scrub
  • DelightEd & Podofyllin
  • xattred, SpotTest, Spotcord, Metamer & xattr tools
  • 32-bitCheck & ArchiChect
  • XProCheck, T2M2, LogUI, Ulbow, blowhole and log utilities
  • Cirrus & Bailiff
  • Precize, Alifix, UTIutility, Sparsity, alisma, Taccy, Signet
  • Versatility & Revisionist
  • Text Utilities: Textovert, Nalaprop, Dystextia and others
  • PDF
  • Keychains & Permissions
  • Updates
  • Spundle, Cormorant, Stibium, DropSum, Dintch, Fintch and cintch
  • Long Reads
  • Mac Troubleshooting Summary
  • M-series Macs
  • Mints: a multifunction utility
  • VisualLookUpTest
  • Virtualisation on Apple silicon
  • System Updates
  • Saturday Mac Riddles
  • Last Week on My Mac
  • sysctl information
Secondary navigation
  • Search

Begin typing your search above and press return to search. Press Esc to cancel.

  • Subscribe Subscribed
    • The Eclectic Light Company
    • Join 8,875 other subscribers
    • Already have a WordPress.com account? Log in now.
    • The Eclectic Light Company
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...