DEF CON 31 - Demystifying (& Bypassing) macOS’s Background Task Management - Patrick Wardle
To retain a foothold on an infected system, most Mac malware will persist; installing itself in a manner that ensures it will be automatically (re)launched each time the infected system is rebooted.
In macOS Ventura, Apple’s rearchitected core persistence mechanisms and added a new security mechanism that alerts the user any time an item is persisted. As the former is both undocumented and implemented in a proprietary manner this poses a problem for existing security and forensics tools (that aim to heuristically detect malware via unauthorized persistence events). On the other hand, the latter is problematic to malware authors, who obviously want their malicious creations to persist without an alert being shown to the user.
In this talk, we’ll indiscriminately provide solutions for all! First, we’ll dive into the internals of macOS’s Background Task Management (BTM) which, as we’ll see, contains a central (albeit proprietary) repository of persistent items. Armed with this information, we’ll release open-source code capable of programmatically enumerating all persistent items from BTM, ensuring security and forensics tools regain compatibility. We’ll also highlight design weaknesses that malicious code could trivially employ to sidestep the new security features of BTM, such that persistence may still be silently achieved.
1 view
0
0
4 weeks ago 01:07:22 6
11-JAN-25 SSP Intentionally Start the California Wildfires, All Countries Temporarily Go to DEFCO...
3 months ago 00:00:00 1
Resonancerz - Let The Galaxy Burn
3 months ago 00:03:09 1
Jay Z - 99 Problems OFFICIAL VIDEO
3 months ago 00:00:00 1
Classic Rock Songs 70s 80s 90s Full Album - Queen, Eagles, Pink Floyd, Def Leppard, Bon Jovi
3 months ago 00:00:00 1
Top 100 Classic Rock Songs Of All Time - ACDC, Pink Floyd, Eagles, Queen, Def Leppard, Bon Jovi
4 months ago 00:01:29 1
Peaceful 31
4 months ago 00:04:54 1
Los Borbones son unos Ladrones VIDEOCLIP + LETRA
4 months ago 01:14:27 1
[Angels Of Love] Dave Morales ’’Revoluciòn’’ live @ Disco Metropolis 31-08-2002
4 months ago 00:03:19 9
NOELIA RODILES & FERNANDO ARIAS en FILARMÓNICA DE ZARAGOZA. Letanía D 343 de
4 months ago 00:46:42 1
ЛУЧШИЕ ИГРЫ про ХОЛОДНУЮ ВОЙНУ
4 months ago 00:35:15 1
The Absolute Craziest Mind Blowing Knives / Stuff at a Knife Show
4 months ago 01:04:33 2
Danny Eaton Guestmix
4 months ago 00:22:46 1
PREPARE YOUR FAMILY FOR A FULL SCALE EVACUATION OF THE URBAN AREAS BEFORE SHTF!
4 months ago 00:42:23 1
⚡ALERT: WW3 GROUND WAR BEGINS! US SENDS TROOPS! KREMLIN/ IRAN EMERGENCY! PUTIN GOES DEFCON 2!
4 months ago 00:02:22 1
Les manifestations après le décès de Philippine
4 months ago 00:44:06 1
DEF CON 25 - Chris Sumner - Rage Against the Weaponized AI Propaganda Machine
4 months ago 00:04:38 1
VIEUX CON !
4 months ago 00:00:00 1
Mamy Samb et Ngoné à Bougane “nagn ko barricadé nakh mou bagna guénati def conférence presse“
4 months ago 00:04:02 1
Resonancerz - Power Of Harmony
4 months ago 00:15:23 1
Russian short film – “Defcon“ (2009)
4 months ago 00:08:22 1
“Rusia entraría en DEFCON4 si Zelensky usa los misiles de largo alcance de EEUU”. Villaroya
5 months ago 01:33:23 1
Cyber Risk Thursday: Internet of Bodies
5 months ago 02:03:39 1
Ori Uplift - Uplifting Only 422 (March 11, 2021) [All Instrumental]