§ Guide

Gatekeeper XProtect And MacOS Malware Artefacts

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 17 pages · 27 min read · Published 2026-09-02

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-09-02. Original material of the practice, free to read, cite and download. The authority behind this subject is NCSC incident management guidance, which you should read alongside this guide. See every guide's author and source.

§ Full text of Gatekeeper XProtect And MacOS Malware Artefacts

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.

Artefacts

What Ran, What Was Blocked, and Whether "a Virus Did It" Holds Up

01 Executive summary

02 The problem in plain English: Macs get malware, and "a virus did it" gets raised

06 Testing the "a virus did it" claim

07 Deployment: breach, c a us at i on and the malware defence

11 Questions to ask · Suggested wording

12 Checklist and red flags · When to involve a digital forensic expert

13 Frequently asked questions

14 Glossary · References · Disclaimer · How a specialist laboratory can assist

Executive summary

The headline point: Macs get malware, and Apple's Gatekeeper and XProtect leave artefacts showing what

ran, was blocked or was quarantined, so those artefacts, with the wider record, both help investigate a genuine

compromise and allow the "a virus did it" defence to be tested even-handedly, at honest confidence.

§ 02 · FIRST PRINCIPLES

The problem in plain English: Macs get malware, and "a virus did

it" gets raised

§ 07 · DEPLOYMENT

Deployment: breach, c a us at i on and the malware defence

§ 12 · QUICK CONTROL

Checklist and red flags · When to involve a digital forensic

expert

When to involve a digital forensic expert

19. The laboratory investigates malware and does not create or deploy it. Through cflab.uk and e-discovery.uk,

What do Gatekeeper and XProtect actually record?

Someone says "a virus did it". How do you test that?

If malware is found, does that prove it was responsible?

Isn't the expert just there to defeat the virus defence?

Working with Computer Forensics Lab

19. The laboratory investigates malware and does not create or deploy it. This guide completes the macOS

Speak to a forensic examiner, not a salesperson.

§ Common questions

Frequently asked questions

Someone says "a virus did it". How do you test that?
Even-handedly, by asking specific questions (
Why the urgency about not shutting the Mac down?
Because compromise evidence is often volatile (
§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp