Gatekeeper XProtect And MacOS Malware Artefacts
17 pages · 27 min read
- Apple and macOS forensics
- Cyber incidents and ransomware
Guide · 17 pages · 27 min read · Published 2026-09-02
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
17 pages · 27 min read
Published by Computer Forensics Lab on 2026-09-02. Original material of the practice, free to read, cite and download. The authority behind this subject is NCSC incident management guidance, which you should read alongside this guide. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.
What Ran, What Was Blocked, and Whether "a Virus Did It" Holds Up
02 The problem in plain English: Macs get malware, and "a virus did it" gets raised
07 Deployment: breach, c a us at i on and the malware defence
12 Checklist and red flags · When to involve a digital forensic expert
14 Glossary · References · Disclaimer · How a specialist laboratory can assist
The headline point: Macs get malware, and Apple's Gatekeeper and XProtect leave artefacts showing what
ran, was blocked or was quarantined, so those artefacts, with the wider record, both help investigate a genuine
compromise and allow the "a virus did it" defence to be tested even-handedly, at honest confidence.
The problem in plain English: Macs get malware, and "a virus did
it" gets raised
Deployment: breach, c a us at i on and the malware defence
Checklist and red flags · When to involve a digital forensic
expert
19. The laboratory investigates malware and does not create or deploy it. Through cflab.uk and e-discovery.uk,
Someone says "a virus did it". How do you test that?
If malware is found, does that prove it was responsible?
Isn't the expert just there to defeat the virus defence?
19. The laboratory investigates malware and does not create or deploy it. This guide completes the macOS
Speak to a forensic examiner, not a salesperson.
17 pages · 25 min read
17 pages · 25 min read
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.