macOS Advanced Evasion

Advanced macOS evasion tradecraft across telemetry, memory, and Apple Silicon.

This advanced track moves beyond one technique or subsystem. You will examine Endpoint Security delivery gaps, process and memory visibility, CPU scanner blind spots, Metal private buffers, command queues, sandbox boundaries, and ANE visibility limits.

Each phase connects operator tradecraft to measurable macOS behavior. You will learn where visibility changes, how to reproduce the condition, and how to present the result without overstating what the evidence proves.

MRTE 01

Managed Mac Operator Foundations

Establish the operating model for a managed Mac before tradecraft: local and domain identity, management layers, security tooling, recon baseline, evidence workflow, and range safety.

6 modules
1.1Managed Mac Operating Model
Locked
1.2Local Accounts, Domain Accounts, and Admin Mapping
Free preview
1.3Management Layers: MDM, Profiles, EDR, and Policy
Free preview
1.4Enterprise Mac Recon Baseline
Locked
1.5Evidence Workflow for Monitored Macs
Locked
1.6Range Baseline and Operator Safety
Locked
MRTE 02

Active Directory, Kerberos, LDAP, and SMB from macOS

Operate against AD-bound Mac environments with native macOS tooling: bind discovery, directory queries, Kerberos tickets, SMB access, LAPS concepts, delegation boundaries, and domain-impact evidence without Impacket-style dependencies.

14 modules
2.1Domain Joined Host Enumeration
Locked
2.2Domain Identity and Bind Confirmation from macOS
Locked
2.3Kerberos on macOS
Locked
2.4Kerberos Tickets and Ticket Evidence
Locked
2.5Native LDAP and Directory Queries from macOS
Locked
2.6SMB Shares from macOS
Locked
2.7SMB Access Control
Locked
2.8Share Triage and Misplaced Enterprise Secrets
Locked
2.9Root-Only Next-Hop Material
Locked
2.10LAPS and Local Administrator Password Workflows
Locked
2.11Delegation and Service Ticket Boundaries from macOS
Locked
2.12Domain Admin Path Assessment from macOS
Locked
2.13Lateral Movement Evidence
Locked
2.14Identity Abuse Cleanup and Reporting
Locked
MRTE 03

Managed Profiles, MDM, and Policy Abuse

Map managed preferences, profile payloads, helper workflows, launchd jobs, and profile-driven trust paths that create root-side enterprise impact.

8 modules
3.1Mapping Profiles, Managed Preferences, Helpers, and LaunchDaemons
Locked
3.2Profile-Driven Remediation Paths
Locked
3.3Trusted Helper and Config Include Abuse
Locked
3.4EDR Visibility and Tradecraft Refinement
Locked
3.5Managed Login Items and Background Services
Locked
3.6Certificate and Trust Profile Abuse
Locked
3.7Local Policy Drift and Enforcement Gaps
Locked
3.8Profile Abuse Reporting and Hardening
Locked
MRTE 04

Enterprise Software, Developer Workstation, and GitHub Abuse

Operate through developer workstation evidence, GitHub state, credential helpers, build trust, self-hosted runners, package scripts, receipts, and deployment helpers.

12 modules
4.1Developer Workstation Recon
Locked
4.2GitHub CLI and Local Auth State
Locked
4.3Git Credential Helpers, SSH Keys, Deploy Keys, and Local Secrets
Locked
4.4Git Hooks, Build Scripts, Workflow Files, and Dependency Trust
Locked
4.5Self-Hosted CI Runner and Build Agent Abuse
Locked
4.6Detection, Cleanup, and Evidence Boundaries
Locked
4.7Installer and Postinstall Review
Locked
4.8Package Receipts and Logs
Locked
4.9Internal Package Cache Abuse
Locked
4.10Deployment Helper Abuse
Locked
4.11Internal Update Channels and Trust Drift
Locked
4.12Enterprise Software Abuse Evidence Package
Locked
MRTE 05

EDR Visibility, Endpoint Security Pressure, and Evasion

Measure what a macOS sensor sees, where ES delivery and YARA coverage fail, how process lineage creates evidence, and how visibility claims should be bounded.

12 modules
5.1macOS EDR Architecture
Locked
5.2Endpoint Security Telemetry Model
Locked
5.3YARA, File Integrity, and Content Scanning
Locked
5.4Process, Parent-Child, and Managed-Path Telemetry
Locked
5.5Noise Shaping and Bypassing Simple Detections
Locked
5.6Reporting Visibility Limits
Locked
5.7Endpoint Security Architecture: Delivery, AUTH, NOTIFY, and Sequence Gaps
Locked
5.8Building a Safe Synthetic Endpoint Security Client
Locked
5.9Controlled Flood Generation and Payload Marker Coordination
Locked
5.10Running the Experiment and Interpreting Bounded Evidence
Locked
5.11Implications, Detection, and Claim Boundaries
Locked
5.12Sensor Failure Modes and Operator Decision Points
Locked
MRTE 06

TCC, PPPC, and Trusted App Abuse

Review TCC databases, PPPC-style trust, trusted helper paths, Automation boundaries, Accessibility, Full Disk Access, and defensive hardening.

8 modules
6.1TCC Database Review
Locked
6.2PPPC Profiles and Pre-Approved Access
Locked
6.3Trusted Helper Abuse
Locked
6.4Automation and Apple Events Boundaries
Locked
6.5Accessibility and Full Disk Access Boundaries
Locked
6.6Trusted App Chain Construction
Locked
6.7TCC Reset, Audit, and Attribution
Locked
6.8TCC and PPPC Reporting
Locked
MRTE 07

Gatekeeper, Notarization, and Enterprise Trust

Cover quarantine, notarization signals, trusted internal applications, signed helpers, enterprise trust assumptions, and review-quality evidence.

6 modules
7.1Quarantine, xattrs, and Gatekeeper Decision Points
Locked
7.2Artifact Blending with Finder Flags, xattrs, Resource Forks, and Dotfiles
Locked
7.3Notarization Signals and Enterprise Trust Assumptions
Locked
7.4Trusted Internal Applications and Helper Workflows
Locked
7.5Signed Helper Workflow Abuse and Review
Locked
7.6Enterprise Allow Lists and Trust Drift
Locked
MRTE 08

Remote Apple Events and Apple-Native Lateral Movement

Use Apple-native discovery and execution paths for SSH-disabled Mac movement, output capture, evidence handling, cleanup, and detection boundaries.

6 modules
8.1Remote Apple Events Discovery
Locked
8.2Remote osascript Execution and Output Capture
Locked
8.3SSH-Disabled Movement with Apple Services
Locked
8.4Apple-Native Service Movement Evidence
Locked
8.5Detection and Cleanup for Remote Apple Events
Locked
8.6Multi-Mac Movement Reporting
Locked
MRTE 09

Network, Proxy, and Tunneling Evasion

Map enterprise network posture, PAC and proxy state, DNS and TLS inspection, SSH tunnels, localhost relays, and proxy-aware tooling from a managed Mac session.

5 modules
9.1Network, Proxy, PAC, DNS, and TLS Inspection Discovery
Locked
9.2SSH Local, Remote, and Dynamic Tunnels
Locked
9.3Localhost Relay and Port-Forwarding Patterns
Locked
9.4Proxy-Aware Tooling with curl, CFNetwork, and NSURLSession
Locked
9.5Tunneling Detection, Cleanup, and Reporting
Locked
MRTE 10

Compiler Trust and Build Workflow Evasion

Use Swift package and compiler-invoked execution paths to understand build trust, package delivery, command evidence, and engagement reporting.

3 modules
10.1The Build Trust Attack Path
Locked
10.2Lab: Package Delivery and Compile-Time Execution
Locked
10.3Engagement Use, Evidence, and Reporting
Locked
MRTE 11

Apple Silicon, GPU, ANE, and Metal Evasion

Accelerator-backed visibility tests around CPU scanner baselines, Metal private memory, blit movement, sandboxed accelerator access, ANE limits, and non-CPU staging.

9 modules
11.1CPU Scanner Baselines on Apple Silicon
Locked
11.2Unified Memory Does Not Mean Unified Visibility
Locked
11.3Metal Shared and Private Buffer Behavior
Locked
11.4Blit Movement and Staging Windows
Locked
11.5GPU Private Memory Tradecraft
Locked
11.6Sandboxed Accelerator Access
Locked
11.7ANE Visibility Limits
Locked
11.8Non-CPU Staging Patterns
Locked
11.9Accelerator Evidence Boundaries
Locked