Tripwires in the Dark: Developing Behavior Detections for macOS
Objective-See Foundation via YouTube
2,000+ Free Courses with Certificates: Coding, AI, SQL, and More
AI Engineer - Learn how to integrate AI into software applications
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore a 45-minute conference talk that examines the evolution of macOS security, focusing on behavior-based detection methods as a critical advancement beyond traditional signature and model-based approaches. Learn how quality data collection, analysis tools, and deep understanding of macOS internals combine with threat actors' Tactics, Techniques, and Procedures (TTPs) to create more effective security measures. Through real-world case studies and an examination of Elastic's advanced behavior detections, discover practical implementations for identifying hidden threats in macOS systems. Gain valuable insights from Senior Security Research Engineer Colson Wilhoit's expertise in developing resilient behavioral-based detections for both endpoint and SIEM systems, while understanding the limitations of relying solely on model and static signature-based detection methods.
Syllabus
#OBTS v7.0: "Tripwires in the Dark: Developing Behavior Detections for macOS" - Colson Wilhoit
Taught by
Objective-See Foundation