Blueprint: Build the Best in Cyber Defense

Jaron Bradley: Securing Enterprise macOS

August 23, 2022 SANS Institute Season 3 Episode 34
Blueprint: Build the Best in Cyber Defense
Jaron Bradley: Securing Enterprise macOS
Show Notes

In this episode of the Blueprint Podcast, we cover monitoring and securing macOS in an enterprise environment at scale with Jaron Bradley, Threat Detection lead at Jamf. We discuss the ups and downs of Apple's approach to macOS data collection over the years, the data sources and types that are accessible to defenders, what 3rd party agents bring to the table for security monitoring, and much more. Plus, Jaron gives us some great bonus tips for finding persistence mechanisms and malicious processes in enterprise macOS devices.

Our Guest - Jaron Bradley

Jaron has a background in Incident Response, threat hunting, and detections development. After focusing on large scale APT attacks he developed an interest in the more niche spaces of lesser explored operating systems. He has experience as both a SOC analyst as well as detections engineering at the endpoint level.Jaron currently works as the macOS Detections Lead at Jamf Threat Labs and manages his own security tools and content for security researchers atthemittenmac.com. He is also the author of OS X Incident Response Scripting and Analysis. A book he claims is slightly outdated but still relevant to a lot of macOS analysis today.

Resources mentioned in this episode

Websites

Conferences

Support for the Blueprint podcast comes from the SANS Institute.

Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube

Follow John Hubbard: Twitter |

Learn more about SANS' SOC courses at sans.org/soc