logoalt Hacker News

wpmtoday at 1:02 AM1 replyview on HN

Endpoint security software on the Mac, if it's worth the hit to system resources that is, inspect every call to exec and fork that occur in the kernel and also inspect those for known attack vectors, malicious scripts, etc. The one I have installed on my work Mac will kill reverse shell attempts before they are run. Will stop keychain attacks. Infostealing (as they can also get every file system op as they are happening in the kernel).

Gatekeeper and Xprotect are good, but there's only so much they can do.


Replies

sciencejerktoday at 8:00 AM

Which do you use/recommend?