Ryan Dowd
@_rdowd
Principal @HuntressLabs | Former Detection & Response Principal @CrowdStrike | macOS Security Enthusiast
ID: 1790694641589010432
15-05-2024 10:44:43
77 Tweet
191 Takipçi
64 Takip Edilen
A side effect of 🍎's privacy mindset: in-memory payloads remain largely invisible/inaccessible to macOS security/3rd-party tools Apple nuked their reflective code loading APIs - but was that enough? 🫣 From #OBTS v7: "Restoring Reflective Code Loading" objective-see.org/blog/blog_0x7C…
This post by Csaba Fitzl has inspired many subsequent successful tcc bypasses, including one I managed to obtain overnight on 15.5 beta 1. Worth giving it a read, a re-read, a re-re-read, etc kandji.io/blog/malware-b…
🎙️😍 Was stoked to talk nerdy on the Mac Admins Podcast! If you're interested in macOS malware, Apple security & detection, and much more, have a listen: linkedin.com/feed/update/ur…