§ Guide, full text

Gatekeeper XProtect And MacOS Malware Artefacts

Macs are susceptible to malware, and Apple's built-in security features, Gatekeeper and XProtect, record activity. These records provide crucial forensic artefacts for investigating genuine compromises and impartially testing the "a virus did it" defence in legal contexts.

17 pages · 27 min read

Loading the PDF reader

Page 1

GATEKEEPER, XPROTECT & MACMALWARE · A GUIDE FOR UK LAWYERS Gatekeeper, XProtect and macOS Malware Artefacts What Ran, What Was Blocked, and Whether "a Virus Did It" Holds Up COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: Macs get malware, and "a virus did it" gets raised 03 How Gatekeeper and XProtect work 04 What the artefacts show: ran, blocked, quarantined 05 Investigating a genuine compromise 06 Testing the "a virus did it" claim 07 Deployment: breach, c a us at i on and the malware defence 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary The headline point: Macs get malware, and Apple's Gatekeeper and XProtect leave artefacts showing what ran, was blocked or was quarantined, so those artefacts, with the wider record, both help investigate a genuine compromise and allow the "a virus did it" defence to be tested even-handedly, at honest confidence.

§ 02 · FIRST PRINCIPLES The problem in plain English: Macs get malware, and "a virus did it" gets raised

§ 03 · HOW THEY WORK How Gatekeeper and XProtect work D OWN LOAD QUARANTINE GATEKEEPER XPROTECT RAN / BLOCKED

Page 2

§ 04 · WHATTHEARTEFACTSSHOW What the artefacts show: ran, blocked, quarantined

§ 05 · INVESTIGATINGACOMPROMISE Investigating a genuine compromise

§ 06 · TESTINGTHEVIRUSDEFENCE Testing the "a virus did it" claim

§ 07 · DEPLOYMENT Deployment: breach, c a us at i on and the malware defence

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE SECURIT Y LOGS / FIREWALL MAC SYSTEM NETWORK / ARTEFACTS MEMORY LOGS END POINT / BACKUPS / MANAGED AV TOOLS SNAPSHOTS CONSOLE

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEGENUINECOMPROMISERECONSTRUCTED EXAMPLE3 · THEMALWAREDEFENCETHEEVIDENCESUPPORTED

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The Mac security and malware checklist Red flags When to involve a digital forensic expert 19. The laboratory investigates malware and does not create or deploy it. Through cflab.uk and e-discovery.uk,

§ 13 · COMMON QUESTIONS Frequently asked questions Do Macs really get malware? What do Gatekeeper and XProtect actually record? Someone says "a virus did it". How do you test that? If malware is found, does that prove it was responsible? Isn't the expert just there to defeat the virus defence? Why the urgency about not shutting the Mac down?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab 19. The laboratory investigates malware and does not create or deploy it. This guide completes the macOS Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, Gatekeeper XProtect And MacOS Malware Artefacts, Computer Forensics Lab, https://e-discovery.uk/library/gatekeeper-xprotect-and-macos-malware-artefacts/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp