00:00:12.240 --> 00:00:16.719
Welcome back to Detection Dispatch, the show for unfiltered SecOps Conversations.
00:00:16.800 --> 00:00:24.079
I'm your host, Alex Hurtado, and today I want to talk about this recurring problem in security that we keep coming back to.
00:00:24.399 --> 00:00:35.679
We are all, I feel like as an industry, very good at looking where we expect things to be, not necessarily where they may be in reality, or the attacker may put it.
00:00:35.920 --> 00:00:42.159
Sometimes a thing that looks super clean and exactly what is exactly what we should be questioning, right?
00:00:42.320 --> 00:00:47.520
The sign binary, the uh the application, the software that we've already trusted.
00:00:47.759 --> 00:00:55.039
If you put it into your rule suppression reference objects, nothing is firing against it.
00:00:55.280 --> 00:01:01.920
Today's conversation is about what happens when the thing you're not looking at is exactly where it is.
00:01:02.079 --> 00:01:07.359
In 2023, a comms app used by hundreds and thousands of organizations shipped a backdoor.
00:01:07.519 --> 00:01:19.599
Uh, it was an executable that was super clean signed, Apple notarized, and the malicious code, Nylives, was loaded at the startup and almost nothing and nobody was looking there.
00:01:19.840 --> 00:01:29.120
Today's guest found it and has spent the last couple of months arguing that we still aren't looking where we're supposed to.
00:01:29.359 --> 00:01:36.159
Patrick Wardle, founder of Objective C Foundation, formerly at NASA and very intimately familiar with alien spies and talking nerdy.
00:01:36.400 --> 00:01:37.840
Welcome to Detection Dispatch.
00:01:38.719 --> 00:01:41.040
Alex, thank you so much for having me on the show.
00:01:41.200 --> 00:01:50.480
Definitely super stoked to talk nerdy about uh macOS security, dialebs, hacks, attackers, maybe not aliens, but all the things.
00:01:52.159 --> 00:01:57.120
We we do too, I gotta say, this is uh a a personal milestone of dispatch.
00:01:57.200 --> 00:02:12.159
Uh we've been we've been following you from the sidelines, from afar, uh since the kind of rapid change and takeover as detection engineering uh has been now more applied in the macOS world.
00:02:12.240 --> 00:02:21.919
Before it was kind of this very undernourished practice, but now I mean you folks like you and Olivia Gallucci, Jaron Bradley have really taken it by the force.
00:02:22.000 --> 00:02:24.800
So I'm as this personal milestone of us.
00:02:25.919 --> 00:02:27.599
Ah, well, those are kind words.
00:02:27.680 --> 00:02:51.840
And I, like I said, really excited to be on the podcast talking about this because I think you mentioned there's still a lot of gaps both in what we're doing, but also in people understanding the threats that are out there, which I think once you know we're on the same page in in the listeners, the greater community, security practitioners, I think we first need a foundational understanding of of the threats and what the advanced adversaries are doing.
00:02:51.919 --> 00:02:57.039
And then hopefully security detections and improved security posture follows.
00:02:57.120 --> 00:02:59.199
So really excited to be talking talking about that.
00:03:00.240 --> 00:03:02.400
It's truly, it's truly just like that.
00:03:02.560 --> 00:03:10.080
It uh I feel like we're as an industry, and especially this community, this is a detection engineering podcast.
00:03:10.159 --> 00:03:18.960
And I feel like we're we very much grew up and are comfortable with how Windows binaries uh traject uh the process lineage.
00:03:19.039 --> 00:03:21.120
It looks a little bit different in the Mac world.
00:03:21.360 --> 00:03:28.400
So any any kind of representation of what we're doing here is fantastic.
00:03:28.719 --> 00:03:36.240
And we and also I can't stop rereading your latest blog on on it.
00:03:36.400 --> 00:03:51.439
But let I want to kind of I want to kind of backtrack the 12 years ago because you showed us, I think this this was one of the first things really that came about when we all didn't think that you know viruses and in in malware on macOS was even a thing.
00:03:51.680 --> 00:04:03.120
12 years ago, you showed us that macOS can be vulnerable, right, to dial-up hijacking, which is also a Windows problem, right?
00:04:03.520 --> 00:04:07.680
But this year in particular, you gave a talk called Dead or Alive.
00:04:07.759 --> 00:04:09.360
So I want to know which one is it?
00:04:09.759 --> 00:04:10.800
Excellent question.
00:04:11.120 --> 00:04:13.840
My take is it's down but not out.
00:04:14.319 --> 00:04:24.000
So in 2012, I uncovered the fact that Mac OS was vulnerable to what is known as a library hijack attack.
00:04:24.319 --> 00:04:38.160
And in a nutshell, what that is, is when an application or program is launched, the loader behind the scenes can look for any dependencies that that program has and load those libraries for the application.
00:04:38.399 --> 00:04:46.319
The problem is sometimes the loader will look in multiple locations and find the legitimate library in a secondary search directory.
00:04:46.480 --> 00:05:05.920
This means a local attacker can plant or drop a malicious library with the same name in a primary search path directory, and naively the loader will then find that and load that into the application, thinking it's doing its job, when in reality it's just introduced malicious code into a otherwise trusted application.
00:05:06.160 --> 00:05:13.839
And when I dove into this and realized that Mac OS was vulnerable to this attack, you could hijack all sorts of applications.
00:05:14.079 --> 00:05:18.560
Bypass gatekeeper, inject into trusted process, persist.
00:05:18.959 --> 00:05:22.240
It was great fun, but also rather worrisome.
00:05:22.319 --> 00:05:30.480
The good news is Apple took this very seriously and introduced a lot of operating system level mitigations specifically to thwart this attack.
00:05:30.639 --> 00:05:33.680
And for all intents and purposes, we thought it was solved.
00:05:33.759 --> 00:05:52.879
Uh I decided to dig into it a little deeper when macOS 26 was released, because as is often the case, Apple has the right idea and takes very aggressive steps to often mitigate things, but oftentimes their implementation, their patch, their security mechanism has some gaps or some flaws.
00:05:53.040 --> 00:06:00.399
And so I found that in certain situations, dial-ed hijacking was still possible, even on the root most recent version of macOS.
00:06:00.480 --> 00:06:02.240
So Apple does have a little bit of work to do.
00:06:02.480 --> 00:06:07.839
The good news, compared to where we were, we are a lot more secure, much, much, much better.
00:06:08.560 --> 00:06:10.800
That's that's very reassuring to hear.
00:06:11.519 --> 00:06:18.079
That's on this side of things, we definitely did see big impact with the uh the ESF framework.
00:06:18.480 --> 00:06:18.959
Definitely.
00:06:19.279 --> 00:06:25.360
Which it it which is what we typically are used to seeing from like the sim world side of it as well.
00:06:25.439 --> 00:06:33.040
There's also, I know, Core Sigma 2 was uh was the manipulation or schema normalization from from Mac.
00:06:33.680 --> 00:06:42.480
And but I I mean, now that more and more, I mean, like you've seen this also take shape, more and more organizations are going very like Mac First.
00:06:42.560 --> 00:06:51.199
Um and it is, and it's like the the number one, almost like preferred selection of some of our most um high privileged users.
00:06:51.279 --> 00:06:58.959
Like people are shipping code uh directly via like AWS OpenVPN on uh directly from their Macs.
00:06:59.199 --> 00:07:02.560
And so this is it's it's if it's still premanent.
00:07:02.720 --> 00:07:12.639
I mean, it what do you see similar models like or affiliate models and traject for like the Amos and the Odysseys of the world?
00:07:12.879 --> 00:07:14.879
Is it kind of still happening?
00:07:15.920 --> 00:07:21.519
So we the good news is that at least tying it back to dialed hijacking, we don't see a lot of it widespread.
00:07:21.680 --> 00:07:26.560
We are seeing more advanced adversaries, though, leverage dynamic libraries.
00:07:26.720 --> 00:07:30.959
Maybe not as much the stealers, but more of the nation state adversaries.
00:07:31.040 --> 00:07:33.519
And they've been doing this for a long time.
00:07:33.759 --> 00:07:37.040
So it's good we have endpoint security now, the framework.
00:07:37.120 --> 00:07:40.480
It does provide us a lot of abilities to see what's going on.
00:07:40.720 --> 00:07:58.959
But one of the main takeaways from my DEF CON talk, where the first half was focusing on the dialeb hijacking and that the fact it was still somewhat alive still today, was taking a broader step back and seeing how dynamic libraries, dialebs have been abused over the years.
00:07:59.040 --> 00:08:00.240
And there's many case studies.
00:08:00.319 --> 00:08:12.000
I mean, Flashback, which is the malware from around 2011, so very old school, but really set the stage for really put to bed the concept of Macs don't get malware.
00:08:12.079 --> 00:08:17.519
It used a neat unpatched vulnerability to infect many, many Mac users around the world.
00:08:18.000 --> 00:08:19.680
And since then, there's been many other examples.
00:08:19.920 --> 00:08:23.439
Equation Group had some Dilib capabilities.
00:08:23.680 --> 00:08:26.399
The 3CX supply chain attack you talked about earlier.
00:08:26.480 --> 00:08:36.159
The attackers package up their dynamic library or their malware in a dynamic library, which was overlooked by Apple, who went and then notarized the application.
00:08:36.399 --> 00:08:42.000
It was overlooked by large EDR companies who examined the application bundle and saw nothing wrong.
00:08:42.399 --> 00:08:59.840
And so, yeah, and so I think one of the main takeaways also from the talk that does include the dialed hijacking is just the fact that over the years, security tools and researchers have really kind of been somewhat blinded and have not been looking at dialeds, even though advanced adversaries have been using AI.
00:09:00.000 --> 00:09:05.039
And the question is first, why have advanced adversaries been using AI?
00:09:05.200 --> 00:09:06.320
And the answer is very simple.
00:09:06.639 --> 00:09:07.440
Well, two reasons.
00:09:07.600 --> 00:09:09.279
First and foremost, it's very, very stealthy.
00:09:09.360 --> 00:09:13.039
So it's very easy to open Activity Monitor, get a list of running processes.
00:09:13.200 --> 00:09:16.480
So if malware is running as a standalone process, it's going to be in that list.
00:09:16.639 --> 00:09:21.919
What Activity Monitor doesn't show you is what libraries are loaded or hosted in that process.
00:09:22.080 --> 00:09:29.039
So if there's a malicious library that's up and running inside one of those processes, you're not going to see that.
00:09:29.279 --> 00:09:32.960
So one, it gives the adversaries a very high level of stealth.
00:09:33.120 --> 00:09:40.559
And then two, anytime a library is loaded into a process, it inherits the privilege, the trust of that process.
00:09:40.720 --> 00:09:46.399
On Mac OS, security decisions are made at the process level, things like TCC permissions.
00:09:46.720 --> 00:09:52.639
If you think, for example, a firewall, it's gonna have a rule that says process is allowed to talk to the internet or not.
00:09:52.799 --> 00:09:58.799
And if there is a library that's loaded within that, it is also going to inherit that same trust.
00:09:58.960 --> 00:10:00.639
So very, very compelling.
00:10:00.720 --> 00:10:07.039
So if you are an adversary listening to this, you should be writing your payloads as dynamic libraries.
00:10:07.200 --> 00:10:13.600
And if you're researchers or a security company or someone who's building a security product, you should be looking at dial-ups.
00:10:13.679 --> 00:10:18.559
And that's something that I think we have not been doing as detection engineers.
00:10:18.720 --> 00:10:21.600
And that's not fully our fault.
00:10:21.840 --> 00:10:27.679
Um the APIs and Apple haven't really provided great ways to enumerate loaded dialebs.
00:10:27.759 --> 00:10:34.399
So that's something we can dive into a little bit more if you want, or we can talk more about uh malware, other things, all the things.
00:10:34.799 --> 00:10:37.039
Yeah, no, that you're absolutely right.
00:10:37.120 --> 00:10:44.080
I I in the last couple of years uh spending writing a lot of uh Mac OS detections.
00:10:44.159 --> 00:10:56.960
I've I looked back on this uh when reading your your article, and it I don't there's maybe three mentions of dialebs across the repositories, a lot of open source repositories too out there.
00:10:57.120 --> 00:11:02.320
Very few mentions of the zero use, like the is platform binary uh field.
00:11:02.799 --> 00:11:05.840
Some of them use like the identity, signing identity.
00:11:06.080 --> 00:11:10.960
And but no, like most of the industry, I feel like we're only looking at command line strings.
00:11:11.440 --> 00:11:15.360
So it is it is definitely like a blind spot, quantified.
00:11:16.159 --> 00:11:28.159
Yeah, and it's one of those things where kind of like cat and mouse, chicken and the egg, maybe I'm conflating my expressions, but you know, we haven't seen a lot of malware abusing dialebs.
00:11:28.399 --> 00:11:32.879
There are a handful of examples of advanced adversaries doing that, which to me means there's enough.
00:11:33.039 --> 00:11:34.240
But also we haven't been booking.
00:11:34.320 --> 00:11:36.879
So are there more we haven't just seen?
00:11:37.120 --> 00:11:39.279
And you know, I include myself uh in this.
00:11:39.440 --> 00:11:45.840
Until recently, I wasn't aware of a way to get a list of loaded dynamic libraries from a running process.
00:11:45.919 --> 00:11:50.080
And this is again largely because Apple puts privacy above security.
00:11:50.240 --> 00:11:53.759
A lot of times they are same same, but sometimes they deviate.
00:11:53.919 --> 00:12:06.000
So, for example, Apple says even if you're a trusted notarized security tool running with elevated privileges and the endpoint security entitlement, you cannot introspect, you cannot read the memory of a remote process.
00:12:06.080 --> 00:12:07.759
And from a privacy point of view, that's great.
00:12:07.840 --> 00:12:15.279
I don't want process A reading my browser memory, which has all my authentication tokens, my keys, all the things.
00:12:15.759 --> 00:12:24.320
But what this means is if that process has a loaded library, previously on older versions of Mac OS, we could read the memory of that enumerate loaded libraries.
00:12:24.559 --> 00:12:28.240
On recent versions of Mac OS, you cannot directly uh access that.
00:12:28.480 --> 00:12:37.679
Luckily, though, there's a very antiquated API that gives you a list of the mappings, and any dynamic library is going to have a mapping associated with it.
00:12:37.919 --> 00:12:46.639
And so what we can do is we can from that essentially infer and get paths to what libraries are likely loaded, and then we can scan those.
00:12:46.720 --> 00:13:10.559
And so as long as the adversary is not doing something super slick like in-memory code execution file base, fileless-based attacks, which they can do, this is at least a great step in the right direction where we can now at least get a list of loaded libraries, and then we can use our detection signatures, Yara, whatever to scan those actual files and see if they're malicious or not.
00:13:10.960 --> 00:13:17.519
I was just gonna say, like listing libraries uh like is getting hard.
00:13:18.080 --> 00:13:19.200
Super hard, especially on Mac.
00:13:20.080 --> 00:13:23.120
Well, I why why does Mac make it so hard to list them?
00:13:23.279 --> 00:13:25.519
Because listing processes on Mac is trivial.
00:13:25.919 --> 00:13:26.559
Yeah.
00:13:27.039 --> 00:13:28.159
That's a great question.
00:13:28.320 --> 00:13:33.120
Previously, like I said, you could open a process, and again, from a privacy point of view, this is horrible.
00:13:33.279 --> 00:13:34.559
From security, it was great.
00:13:34.799 --> 00:13:43.200
And so you could open the process, and you know, within that there were structures, basically a list, an exported list of the libraries it had loaded.
00:13:43.279 --> 00:13:46.559
And you could just grab that and walk over that, and everyone was happy and well and good.
00:13:46.720 --> 00:13:49.120
But that required you to be able to read remote memory.
00:13:49.279 --> 00:13:53.840
Um so from a privacy point of view, I think Apple basically said, nope, you can't do that.
00:13:54.000 --> 00:13:58.720
And kind of also maybe there was no demand for this capability.
00:13:58.879 --> 00:14:05.840
And I think knowing what libraries are loaded, uh, I don't know if that's I don't think that's really a privacy concern, but I think no one was asking.
00:14:05.919 --> 00:14:13.440
And so Apple said, okay, well, you can't read the memory, which kind of shut the door on the previous technique of enumerating loaded libraries.
00:14:13.600 --> 00:14:16.000
No one's asking for it, so all is good.
00:14:16.240 --> 00:14:18.639
And so I think that's kind of where we're at now.
00:14:18.879 --> 00:14:28.480
The good news is with endpoint security, even though there's no direct event for library was loaded, which I would love, you can register for mapping events.
00:14:28.639 --> 00:14:33.919
Now, mapping events could be you know process mapping in uh a file it wants to read.
00:14:34.159 --> 00:14:39.600
It could be the browser mapping in a chunk of memory to do some you know JIT stuff.
00:14:39.759 --> 00:14:41.279
Or it could be a loaded library.
00:14:41.440 --> 00:14:50.480
So we can register for mapping notification and off events, and then from that we can check if it's an executable mapping, and then from that we can get a path.
00:14:50.639 --> 00:14:57.360
So again, we can kind of indirectly get library loading events, which step in a great direction.
00:14:57.519 --> 00:15:06.240
I wish it was more easy and comprehensive and we didn't have to jump through all these hoops, but compared to where it was, it's like a 90% solution.
00:15:06.320 --> 00:15:08.960
I am very happy because previously it was like zero.
00:15:09.360 --> 00:15:10.559
Nothing at all.
00:15:11.120 --> 00:15:11.840
Nothing at all.
00:15:11.919 --> 00:15:18.000
And so Apple asks me often, sometimes I don't know if they're joking or not, they're like, what would you like to see at endpoint security?
00:15:18.080 --> 00:15:21.679
And one of my answers to the would be like, give me a loaded library event.
00:15:21.919 --> 00:15:23.440
Like, just let me register for that.
00:15:23.519 --> 00:15:29.759
And anytime a library is loaded, give me a callback with the path to the library, and I would be a super happy camper.
00:15:30.080 --> 00:15:33.840
So doing God's work, Patrick, for us on behalf of the community.
00:15:34.159 --> 00:15:36.159
Restoring the Garden of Eden.
00:15:37.200 --> 00:15:39.039
It's an Apple joke somewhere in there.
00:15:39.440 --> 00:15:40.320
Of course.
00:15:40.639 --> 00:15:54.480
When a security tool sees like a file access from inside a hijack process per se, or a library, what what then would be the detection opportunities?
00:15:54.960 --> 00:15:55.840
Oh, that's a great question.
00:15:56.000 --> 00:16:05.039
That's one of the challenges about dialeds, is because, so for example, in my hijack example, I just looked at what applications were vulnerable on my system.
00:16:05.279 --> 00:16:06.399
Photoshop was one.
00:16:06.480 --> 00:16:10.720
I use Photoshop a lot for image editing, slide design.
00:16:10.799 --> 00:16:12.240
I, you know, in a previous life.
00:16:15.600 --> 00:16:17.120
Oh no, oh no.
00:16:17.440 --> 00:16:18.320
Okay, I won't judge.
00:16:18.399 --> 00:16:18.879
I won't judge.
00:16:18.960 --> 00:16:20.000
No, Canva is now great.
00:16:20.159 --> 00:16:25.440
Uh yeah, I I think in a previous life I was a graphic designer or something, but maybe we'll save that for another podcast.
00:16:25.600 --> 00:16:28.480
But Photoshop is vulnerable to a dial-up hijack attack.
00:16:28.639 --> 00:16:33.120
And one of the neat things about Photoshop from an attacker's point of view, at least on my box, it's always running.
00:16:33.600 --> 00:16:34.720
And it has a lot of access.
00:16:34.799 --> 00:16:45.360
It's allowed to talk to the internet, my firewall rules allow it because it's got to do licensing checks, syncing with the cloud, and then it has to have access to my photos and files, so it has certain TCC privileges.
00:16:45.519 --> 00:16:54.399
So once my library is now loaded into the context of that, in this case via a library hijack, I inherit all the privileges of Photoshop.
00:16:54.480 --> 00:17:04.319
And to your point, then, as soon as my malware, my malicious dialeb, starts reading files, yes, endpoint security will flag those, but guess what endpoint security is gonna tell us?
00:17:04.400 --> 00:17:07.359
It's gonna say Photoshop is accessing this files.
00:17:07.599 --> 00:17:13.119
So there's nothing in the endpoint security event that says it was a specific library.
00:17:13.200 --> 00:17:16.240
The granularity of endpoint security is just at the process levels.
00:17:16.480 --> 00:17:29.759
So what you then would probably have to do is if you start seeing, let's stick with the Photoshop example, it doing anomalous things, maybe talking to a network endpoint you don't recognize, or like accessing files that Photoshop normally wouldn't.
00:17:29.920 --> 00:17:35.039
What I would then do is enumerate all the loaded libraries and then go and scan those individually.
00:17:35.200 --> 00:17:46.880
Again, though, you can see this is like super indirect and it's like very icky compared to, okay, here's a list of processes, let's scan them, flag the malicious ones, flag the ones that aren't signed, etc.
00:17:47.039 --> 00:17:47.279
etc.
00:17:47.839 --> 00:17:50.319
So yeah, the struggle is real.
00:17:50.799 --> 00:18:02.079
I was gonna say it's it is not, it it is a little bit, it takes a little bit of a multi-step pivoting versus just like a maybe advanced correlated join of a query.
00:18:02.799 --> 00:18:10.880
Yeah, it takes a but I would say this is more of a threat hunting application versus yeah, versus like an ongoing scheduled detection.
00:18:10.960 --> 00:18:11.119
Yeah.
00:18:11.519 --> 00:18:16.799
Welcome to the world of detection and security tooling on Mac OS.
00:18:16.880 --> 00:18:21.119
I mean, it's great job security for all of this, but it's never as simple as it could be.
00:18:21.359 --> 00:18:41.519
That having been said, I think if you are collecting enough events, so if you are collecting mapping events and file events and network events, you could then have enough metadata or enough events that then detection rules, detection events could flag something as almost being malicious.
00:18:41.759 --> 00:18:44.160
Um and so I think that's the approach I would take.
00:18:44.319 --> 00:18:46.960
Just try to collect all these disparate pieces.
00:18:47.039 --> 00:18:49.200
And then yeah, it's maybe more threat-hunting.
00:18:49.279 --> 00:19:04.400
But I think if you took all those events and you know, fed them into a seam, and then your sigma rules, yarrules, whatever your detection rules could ingest multiple points, uh data points, I think you could do some really neat uh heuristics.
00:19:04.559 --> 00:19:08.960
But again, they would depend on correlating many disparate things.
00:19:09.039 --> 00:19:13.599
Um and exactly like you said, kind of like hoops and pulling things uh together.
00:19:13.759 --> 00:19:15.759
But like I said, it's never easy on my class.
00:19:16.799 --> 00:19:17.759
It never is.
00:19:18.000 --> 00:19:29.920
I I you know what I when I was in like in my college days, I can't, I I I never I you know how you always like remember your your most like favorite professors.
00:19:30.400 --> 00:19:31.359
Yes, for sure.
00:19:31.599 --> 00:19:36.799
Uh and for some reason it they ingrained uh this framework into my head.
00:19:36.880 --> 00:19:50.880
And it's like this process of dissecting and really doing this kind of legitimacy assessment of how we look at processes and like process lineage and privilege.
00:19:51.039 --> 00:19:58.480
Um I'm gonna share it because I want to kind of like brainstorm what the equivalent would be for mapping together.
00:19:58.960 --> 00:20:01.519
Um so this is the one for Windows.
00:20:01.680 --> 00:20:04.400
So for example, it's it's called a three by four.
00:20:04.720 --> 00:20:11.119
And it's you look at the parent, the subject, and then the child process if there was one.
00:20:11.359 --> 00:20:14.160
And if there wasn't one, like you would just not fill it out.
00:20:14.319 --> 00:20:17.759
But for each lineage, then you assess four areas.
00:20:18.000 --> 00:20:22.799
You assess whether the authenticity of that process is like it's signed, right?
00:20:22.880 --> 00:20:29.119
Or maybe it's like it's like it's not signed, or maybe it is signed, but it's like it's an expired signature.
00:20:30.799 --> 00:20:33.519
And then you look at the parameters.
00:20:33.680 --> 00:20:36.480
So what is happening in the command line arcs, right?
00:20:36.720 --> 00:20:38.720
Then the behaviors, what what did it even do?
00:20:38.799 --> 00:20:48.559
Like it what that that can get you that kind of ground ground setting if if it's normal, if it's not normal, this is really where we spend the majority of your time.
00:20:48.799 --> 00:20:51.599
And then the and then the connections, like what what did it make?
00:20:51.759 --> 00:20:52.960
What what was the connection?
00:20:53.119 --> 00:20:57.680
So you look at each of each four things across the subject, the parent, the child.
00:20:57.759 --> 00:20:59.759
So you technically have to look at 12 things.
00:20:59.920 --> 00:21:05.759
But once you start doing it like a lot, you it it's kind of like it's it's very, you do it pretty fast.
00:21:07.519 --> 00:21:09.920
I'm not gonna like make a checkbox of every little thing.
00:21:10.240 --> 00:21:11.039
Sure, sure, sure.
00:21:11.279 --> 00:21:14.319
Yeah, you got you you did it pretty on a on a pretty fast level.
00:21:14.480 --> 00:21:17.279
And then if any one of the it's like a traffic light protocol.
00:21:17.359 --> 00:21:23.440
So if any one of these things was red, it it it is probably something you should double tap into.
00:21:24.480 --> 00:21:28.640
For Mac, I feel like I it it's not a one-to-one, would you say?
00:21:29.039 --> 00:21:29.599
True.
00:21:29.839 --> 00:21:31.039
Yeah, I would agree.
00:21:31.119 --> 00:21:32.480
Uh first, it's super interesting.
00:21:32.559 --> 00:21:33.920
I like all the pieces.
00:21:34.000 --> 00:21:37.440
Uh just kind of pondering this all, especially the last two.
00:21:37.519 --> 00:21:39.440
I think that's where I live and breathe.
00:21:39.680 --> 00:21:42.319
And I mean, well, even the first one, the authenticity.
00:21:42.480 --> 00:21:47.039
The great thing about Mac OS is we have so much code signing information.
00:21:47.200 --> 00:21:50.559
Like, it's really great to be basically everything is signed.
00:21:50.720 --> 00:21:56.640
We can see if things are notarized, and so immediately that tells us if something is tampered from, it tells us where it's from.
00:21:56.880 --> 00:21:59.119
So it's really good for false positive reduction.
00:21:59.279 --> 00:21:59.759
Most of the tools.
00:22:00.240 --> 00:22:01.839
I write are heuristic based.
00:22:03.440 --> 00:22:09.039
You know, like to detect ransomware, we can look for untrusted processes rapidly creating files.
00:22:09.279 --> 00:22:11.279
And but legitimate applications do that.
00:22:11.440 --> 00:22:16.400
For example, Chrome, when it downloads safe browsing, it downloads a whole bunch of files that are encrypted.
00:22:16.559 --> 00:22:24.319
But very quickly, we can see the processes signed by Google proper, because on macOS everything has to be signed, and say, okay, this is Google.
00:22:24.400 --> 00:22:25.920
It's it's it's it's it's trusted.
00:22:26.000 --> 00:22:33.200
Whereas with Windows, my understanding is code signing isn't as mandatory or isn't as uh kind of all the things.
00:22:33.839 --> 00:22:46.400
I do like though, especially the last two pieces, the behaviors and the connections, because to tie it back to our discussion about dynamic libraries, it's almost like we need more granularity than the process.
00:22:46.880 --> 00:23:00.079
And so by looking at what what might otherwise be a trusted process, if it's doing something funky, I think that is an area where maybe in the coming years we'll see more research being done into that.
00:23:00.240 --> 00:23:04.480
Um I'm also thinking just with agents and AI and LLMs, right?
00:23:04.640 --> 00:23:11.519
A lot of times you have agents executing platform binaries to perform tasking.
00:23:11.680 --> 00:23:24.400
And you know, if those agents ever got coerced or manipulated or subverted, might be a better term, you know, from the outside, you might not see anything wrong with the agent, but you might notice it misbehaving.
00:23:24.559 --> 00:23:32.319
So again, I really can see, at least on Mac OS, focusing more on the behaviors and the connections is super powerful.
00:23:32.400 --> 00:23:48.880
And actually for the 3CX attack, at least on Windows, that is how CrowdStrike originally detected that uh there was a supply chain attack against this large PBX VoIP company because they noticed the window version of their app was talking to like a new strange domain that had just been registered.
00:23:48.960 --> 00:23:52.400
And they were like, wait a minute, like that's super, super, super odd.
00:23:52.640 --> 00:24:01.359
Yeah, so I think there's a lot of pieces to pull out, but I'm a big fan of this idea, especially when we get into the behaviors and the network activity.
00:24:02.559 --> 00:24:04.160
Yeah, I appreciate that.
00:24:04.319 --> 00:24:15.680
And you're right, the follow-on behavior, follow-on connections, follow-on really anything as it goes down the attack chain pipe is is really what to stitch together.
00:24:15.920 --> 00:24:23.359
And also the I gotta say, the waves in the background is just the most relaxing thing ever.
00:24:24.000 --> 00:24:24.559
There's waves.
00:24:24.799 --> 00:24:26.160
These listeners are also catching.
00:24:26.240 --> 00:24:27.279
I think I'm catching that.
00:24:27.519 --> 00:24:29.039
Is that the one of the waves?
00:24:29.680 --> 00:24:30.160
Maybe.
00:24:30.319 --> 00:24:32.880
I am looking out on the sea.
00:24:33.039 --> 00:24:34.400
So yeah.
00:24:34.960 --> 00:24:38.160
Patrick has a really nice view into the Mediterranean.
00:24:38.240 --> 00:24:41.440
Um and I'm I'm catching some of the some of the nice waves.
00:24:41.920 --> 00:24:42.559
Okay, perfect.
00:24:42.640 --> 00:24:43.200
As long as it's not.
00:24:44.480 --> 00:24:46.240
It sounds like my my sound machine.
00:24:46.319 --> 00:24:47.359
I put on that nice.
00:24:48.000 --> 00:24:49.839
Okay, so it's it's calming then.
00:24:50.319 --> 00:24:51.200
It's calming.
00:24:51.359 --> 00:24:52.480
Of course it is.
00:24:52.720 --> 00:25:03.920
The other thing, too, as we're thinking about some some more mitigations against what we can and can see, like the authenticity, I guess, to continue off of that.
00:25:04.160 --> 00:25:08.319
In the case of dial-ebs, I mean it would have, it would have come in.
00:25:08.640 --> 00:25:10.079
You can't just do one or the other, right?
00:25:10.160 --> 00:25:14.559
Like, because it would have come in as completely notarized, completely authenticated.
00:25:14.880 --> 00:25:16.640
It's a legitimate certificate.
00:25:16.880 --> 00:25:20.799
So it's so it's so important to couple all of that follow-on.
00:25:21.519 --> 00:25:21.839
Exactly.
00:25:22.000 --> 00:25:35.200
We really need a lot of events, especially for the more complex attacks, to gather enough behaviors that then our threat hunting or detection can actually start detecting anomalies and then flag something as uh flag something as a myth.
00:25:36.319 --> 00:25:57.839
On the topic of agents, um, I went in a rabbit hole a while ago and uh trying to, yes, basically um find detection opportunities for when agents go rogue or when uh to distinguish kind of like malicious uh user-attempted attempts versus versus maybe just like an agent doing what they're supposed to be doing.
00:25:58.000 --> 00:26:06.720
And the specific opportunity, uh detection opportunity was like multiple reaches into credential stores, like within like a short amount of time.
00:26:06.880 --> 00:26:14.079
But but it kept tripping me up because that's also very similar to other behavior that I have looking for infostealer stuff.
00:26:14.319 --> 00:26:16.240
They do the same effectively the same thing.
00:26:16.799 --> 00:26:24.240
So it's a it's a very high-range, uh, not not the best precise, most precise detection I I guess I've written.
00:26:24.799 --> 00:26:26.960
But it's very interesting.
00:26:27.440 --> 00:26:29.039
It's very similar behavior.
00:26:29.440 --> 00:26:30.079
It is.
00:26:30.319 --> 00:26:41.359
And not to cut you off, uh, but I really like that you brought up this point because traditionally, dialebs aside, the vast, vast, vast majority of MacMal RAN as a standalone process.
00:26:41.440 --> 00:26:48.240
And so looking at process hierarchies, looking for standalone binaries that were doing weird stuff was like super solid.
00:26:48.319 --> 00:26:49.920
It was our bread and butter.
00:26:50.240 --> 00:26:57.440
Now with agents, it's like, wow, because they're executing everything with like shell commands and executing platform binaries.
00:26:57.680 --> 00:27:15.920
And so it really is super challenging to detect if that, exactly like you said, if that is normal behavior or if that is anomalous, and is that anomalous or malicious because of a user instructing the agent to do something suspicious, maybe malicious insider or something along those lines?
00:27:16.240 --> 00:27:28.559
Or is that a rogue or a subverted agent that is somehow doing something negative, malicious on behalf of you know, someone else, another program commanding it to do that?
00:27:28.720 --> 00:27:35.200
Um, and so I think there's a lot of work that, uh research that's going on there because I mean it's crazy.
00:27:35.279 --> 00:27:40.160
We're like very strict about what we run on our systems, and then we just like let these agents go to town.
00:27:40.240 --> 00:27:41.519
And it's kind of like, damn.
00:27:41.680 --> 00:27:49.039
And the people running the agents, well, it's everybody, but it's the developers and it's the people who have probably access to sensitive IP.
00:27:49.599 --> 00:28:02.480
And so I think we see a lot of research, a lot of talks, uh, a lot of new detections around this area because I think it's one of the things that's driving Mac adoption and Apple hardware, unified memory, there are chips.
00:28:02.559 --> 00:28:07.200
It's like incredible for agents and you know AI stuff.
00:28:07.359 --> 00:28:12.799
And so I think a lot more people are diving into the Apple hardware space because of AI.
00:28:12.960 --> 00:28:31.519
And so there's some unique security challenges that I think you and I and others in our space are really gonna have to think long and hard and and do some new research to figure out exactly like you said, how do we classify if an agent's misbehaving, behaving, or has been subverted, or if it's malware masquerading along those same lines.
00:28:32.000 --> 00:28:32.400
Yeah.
00:28:32.960 --> 00:28:44.720
I'm thinking maybe maybe uh dialebs awareness has to be then built into what an agent is looking at, or or would it have to be built at like added down later in the pipeline?
00:28:45.440 --> 00:28:46.960
Oh, that's a great question.
00:28:47.519 --> 00:28:53.200
You know, I think one of the challenges, you know, there's like multiple opportunities to detect things along the way.
00:28:53.359 --> 00:28:59.039
So, for example, if you're doing a dialed hijack attack, something has to plant that library into the application.
00:28:59.119 --> 00:29:02.240
And so there's an opportunity there to detect something amiss.
00:29:04.160 --> 00:29:05.599
Yeah, detect Yeah.
00:29:05.839 --> 00:29:10.640
And so detecting a hijack after the fact is definitely more challenging.
00:29:10.960 --> 00:29:15.200
And so, you know, as we always say, it's a very holistic defense in depth approach.
00:29:16.000 --> 00:29:17.359
Buttons in death, of course.
00:29:17.440 --> 00:29:18.799
We use that here all the time.
00:29:19.599 --> 00:29:30.799
And so, you know, with agents and dialebs, it's really just like uh my perhaps naive take is like you just need to collect more events of what's happening.
00:29:31.039 --> 00:29:48.240
And then, you know, the good thing is with all LLMs, there was a great talk, I think it was a year or two years ago at uh Objective by the C, uh, Chemo from OpenAI, who's gonna be speaking again um this year, really talked about okay, you get all these events, okay, now you can actually feed those into LM LLMs and look for anomalies.
00:29:48.319 --> 00:29:50.720
Like this is a really actually great thing.
00:29:50.880 --> 00:30:03.440
So in the past, maybe we didn't want to collect too many events, and still we shouldn't collect all the events, but now I feel like we have these tools in our arsenal that want as much data as we can give them.
00:30:03.519 --> 00:30:20.400
And so if there's a way for us to do that somewhat efficiently, collect a lot of the mapping events that can lead to dialeds, monitor what the agents are doing, and collect all that, feed that into our detection back ends where we're running our rules, maybe add some LLMs, examining that into the mix.
00:30:20.559 --> 00:30:30.960
I think that's how you get a more comprehensive approach that maybe can detect some of these more challenging dialed-based attacks or rogue agents.
00:30:31.279 --> 00:30:32.079
And again, we'll see.
00:30:32.160 --> 00:30:41.200
It's kind of my thought for the current time, and I could be proven wrong, but it seems like a good way to uh dive into, especially again if we have these LLMs that can help us on the back end.
00:30:41.920 --> 00:30:42.480
Absolutely.
00:30:42.640 --> 00:30:49.279
And by tools, uh, do you happen to mean the Lulu's tool that you also happen to run to write?
00:30:49.759 --> 00:31:03.920
I'm more thinking of like enterprise grade security tools that are collecting a lot of events on the system and then kind of can feed that into a seam and then on the back end run depiction roles.
00:31:04.160 --> 00:31:11.680
Yeah, a lot of the tools I write, for example, when you you mentioned Lulu, free open source firewall, it kind of does like do one thing, do it well.
00:31:12.000 --> 00:31:17.039
The idea is it detects if an unauthorized process is connecting out.
00:31:17.279 --> 00:31:24.160
And you know, I think the great thing is I spend a lot of time pondering attacks and also writing security tools.
00:31:24.240 --> 00:31:35.920
And so that intersection is is really neat because, for example, Lulu, well, the operating system gives Lulu network streams to examine and it ties them back to the process, not to the dialed.
00:31:36.079 --> 00:31:45.119
So if I have a rule that says Photoshop is allowed and there's a new network connection from a malicious library, there's a few challenges.
00:31:45.279 --> 00:31:54.240
First, Lulu checks the code signing information of the process, but a dynamic injected library does not modify the code signing information of the process.
00:31:54.319 --> 00:31:56.559
So the APIs come back and say everything looks good.
00:31:56.720 --> 00:31:57.839
Apple's APIs.
00:31:58.480 --> 00:32:04.640
So what Lulu can then do is you can have you have to basically have specific rules that say, oh, it can only talk to these certain endpoints.
00:32:04.720 --> 00:32:14.319
And if there's a new connection to a command and control server in, you know, Russia or somewhere that Photoshop normally doesn't tech to, that is the way a firewall can uh detect that.
00:32:14.480 --> 00:32:22.079
Because again, just to go back to this fact, otherwise, the events that the operating system is delivering to the security tool, the granularity is just at the process level.
00:32:22.160 --> 00:32:28.319
So there's no way for these security tools to say, oh, this network connection is actually coming from this library in this process.
00:32:28.559 --> 00:32:43.839
If we had that, that would be insane because immediately we could check the code signing information of that dynamic library and say, wait a minute, there is an you know, uh an ad hoc signed library that's loaded into Photoshop, like talking to some unknown command and control server.
00:32:44.000 --> 00:32:44.799
Huge red flag.
00:32:44.880 --> 00:32:46.960
But currently we don't have that information.
00:32:47.119 --> 00:32:49.839
So if anyone's from Apple is listening, help us.
00:32:51.200 --> 00:32:51.759
Please help us.
00:32:51.920 --> 00:32:52.720
It's so crazy.
00:32:52.799 --> 00:32:56.319
You can run things inside of like another application.
00:32:56.960 --> 00:32:57.200
Yeah.
00:32:57.440 --> 00:33:02.400
Apple does, to their credit, really has reduced that attack surface because they realize that.
00:33:02.480 --> 00:33:03.920
Uh but again, there's always trade-offs.
00:33:04.000 --> 00:33:06.160
Things like Photoshop needs to support plugins.
00:33:06.240 --> 00:33:08.799
And so plugins by definition are third-party code.
00:33:09.039 --> 00:33:12.319
Now with agents, you know, there's all these plugins that people are running.
00:33:12.480 --> 00:33:15.680
So it's like we take one step forward, two steps back.
00:33:15.839 --> 00:33:20.400
Again, great for Java security, but otherwise, again, the struggle is real.
00:33:22.559 --> 00:33:24.240
So click fix, right?
00:33:24.400 --> 00:33:28.960
Click fix, paste this into your terminal, uh, coming for all of us right now.
00:33:29.039 --> 00:33:35.680
It's a dominant Mac OS delivery delivery vector, but also very much still in the Windows world as well.
00:33:36.000 --> 00:33:42.240
It's and it's not an exploit, and it's not even malware until I guess the user cooperates.
00:33:42.480 --> 00:33:47.839
But I gotta ask, like, does it bother you as someone who hunts Apple Zero Days for a living?
00:33:48.480 --> 00:33:55.039
I saw a bumper sticker, and I don't always like repeating this because I don't like to assign blame so indiscriminately.
00:33:55.200 --> 00:34:00.079
But the bumper sticker in the context of cybersecurity was there is no patch for human stupidity.
00:34:00.480 --> 00:34:02.400
And you know, harsh.
00:34:03.119 --> 00:34:03.839
Harsh.
00:34:04.400 --> 00:34:06.799
But you know, if people Yeah.
00:34:07.920 --> 00:34:09.039
But like But it's true.
00:34:10.239 --> 00:34:17.599
But you know, what is Apple to do if people are cutting and pasting commands from the internet, running them in a terminal?
00:34:17.760 --> 00:34:23.679
Um and so what the attackers are really doing are basically exploiting users' naiveness.
00:34:23.920 --> 00:34:30.079
And again, I don't blame the users because always, uh, because some of these are very sophisticated attacks, right?
00:34:30.239 --> 00:34:38.000
It's like we've seen instances where a user will ask an LLM for a solution, and the link the LLM recommends is something that has a click-fix solution.
00:34:38.239 --> 00:34:42.079
And so it's like, okay, maybe the user shouldn't have blindly trusted the AI.
00:34:42.159 --> 00:34:43.440
That's a whole separate discussion.
00:34:43.679 --> 00:34:49.840
But you know, or we see these contagious interview, I think that's the name of the um DPRK associated.
00:34:49.920 --> 00:35:01.199
You know, someone jumps on a Zoom call for a potential job uh interview, which these days are difficult to get, and then the company is like, oh, run this to fix the connection.
00:35:01.280 --> 00:35:03.360
And it's like, okay, I could see users falling.
00:35:03.840 --> 00:35:12.079
But all exploits the fact that the operating system is limited if the user is performing specific examples.
00:35:12.159 --> 00:35:24.800
And I think it's worth pointing out that when you run something from the terminal, it really sidesteps by design a lot of Mac OS's built-in security checks, like uh notarization checks, gatekeeper checks, etc.
00:35:24.960 --> 00:35:30.960
It's a little bit more nuanced, but generally speaking, running something from the terminal gives a lot more leeway.
00:35:31.039 --> 00:35:36.559
And so attackers realize that, which is why click fixed is now um so prevalent.
00:35:36.800 --> 00:35:44.880
So, yeah, I mean it is a little disheartening where people are still running malicious commands uh in the terminal.
00:35:45.039 --> 00:36:01.840
I looked at this malware sample five, six, seven years ago now, and it was someone who was posting commands in a Telegram channel for cryptocurrency users, and I named the malware dummy because I was like, this is so dumb.
00:36:02.000 --> 00:36:03.920
Like, this is such a lame attack vector.
00:36:04.079 --> 00:36:13.599
But it was very like, I guess, ahead of its time, because like exactly like you said, Steelers now, their preferred mechanisms are click fix.
00:36:13.920 --> 00:36:20.320
And you know, I talk to companies that monitor a lot of systems, and they say, yeah, like users fall for this stuff all the time.
00:36:20.400 --> 00:36:21.920
So we can't discount it.
00:36:22.000 --> 00:36:28.159
Uh and so the question then becomes okay, what are the technical solutions we can implement?
00:36:28.239 --> 00:36:38.159
Um and so one of my tools monitors for basically copying paste, and it sees when you're copying something from the browsers into the terminal, it's like, yo, wait a minute, are you sure you want to do this?
00:36:38.239 --> 00:36:43.440
And now actually Apple implements um something uh similar as well.
00:36:43.920 --> 00:37:02.559
So no, I mean even with all of that, I mean, I till this day, I feel like I would be very fooled by any uh any trace of where to get oysters in Chicago or where like where where where the best mart dirty martini is.
00:37:02.719 --> 00:37:04.639
Like how to hack Alex.
00:37:04.960 --> 00:37:06.159
No zero-day meeting.
00:37:06.880 --> 00:37:07.360
No day.
00:37:08.480 --> 00:37:13.199
That would get me command command C, command v into my terminal.
00:37:13.360 --> 00:37:18.800
Like if that's gonna give me the CSV of all of the best like$1 oysters.
00:37:18.960 --> 00:37:29.920
Like you know, and to be fair, I will throw myself into this as well that you know I'm copying and pasting stuff all the time, you know, output from agents and stuff.
00:37:30.000 --> 00:37:35.599
So I think it is easy to you know point at users and be like, oh, there's no better falling for these attacks.
00:37:35.679 --> 00:37:37.440
This is ridiculous, like it's their fault.
00:37:37.519 --> 00:37:40.800
But no, the reality of this is I think we're all susceptible to this.
00:37:40.880 --> 00:37:48.000
And adversaries are very opportunistic, very wily, and they wouldn't be doing it if it if it didn't work.
00:37:48.079 --> 00:38:03.679
And you know, again, the problem with these stealers is once they run, it's like you basically need only one to run in an organization, and it gets all the creds it needs, and then this opens the door for a lot more impactful attacks, ransomware, or just uh beta exfiltration.
00:38:03.760 --> 00:38:08.559
And so again, we sometimes discount a lot of these steelers because yeah, a lot of them are pretty basic.
00:38:08.639 --> 00:38:31.199
They're not super elegant, they're not written very well, but the fact of the matter is they are you know doing their job very successfully, and the fact that really I think they're the most prolific threat targeting Mac users, even in the enterprise, is a testament to you know their their success and their um efficiency.
00:38:31.599 --> 00:38:34.079
There's not one day it hasn't come up.
00:38:34.239 --> 00:38:40.719
I I feel in my last two weeks worth of meetings, that's that's that's that's the number one thing on the agenda.
00:38:40.960 --> 00:38:47.440
It's uh let's let's start off by talking about coverage for click fix for both across the the different layers.
00:38:47.599 --> 00:38:51.280
The endpoint, the identity side, the the network side.
00:38:51.440 --> 00:38:56.000
A lot of it is I I think concentrates in uh the network side.
00:38:56.079 --> 00:39:04.320
So like Z, if anyone's got Zeke running, that that the follow-on connection behavior is really the cutting it or catching it after.
00:39:05.199 --> 00:39:09.199
Post post command V or uh command uh yeah, command V.
00:39:09.760 --> 00:39:13.679
Um which sucks because you can't really get it at the beginning, right?
00:39:13.760 --> 00:39:17.840
Because it doesn't, there's no lineage, it doesn't go from browser to execution.
00:39:17.920 --> 00:39:21.599
It's like a user, it's like it's like clipboard to execution.
00:39:21.920 --> 00:39:22.400
Yeah, yeah.
00:39:22.480 --> 00:39:25.039
And it's like through the pasteboard daemon and all this up.
00:39:25.360 --> 00:39:30.079
But I am optimistic because two things.
00:39:30.239 --> 00:39:31.440
Well, I guess one thing.
00:39:31.679 --> 00:39:38.400
So there is a undocumented endpoint security event that allows you to register for clipboard events.
00:39:38.480 --> 00:39:41.199
Um, and I think this is something that's done on iOS already.
00:39:41.280 --> 00:39:52.320
I mean, there's not endpoint security, but you know, on iOS, when you like paste in an app, there's an alert and the operating system is like, hey, do you want Google Maps to you know allow you to paste into it or something?
00:39:52.559 --> 00:40:01.840
And so maybe the technology is very somewhat similar, but I actually looked into um the private, let's call it, or undocumented endpoint security event.
00:40:02.079 --> 00:40:09.599
And if it was available to security tools, it would be incredibly helpful because you can register for an authorization event.
00:40:09.760 --> 00:40:23.119
When there is a paste event, the operating system will actually pause that event and allow you to see as an endpoint security client the source and destination, so browser to terminal, uh, and also the contents.
00:40:23.199 --> 00:40:28.000
So you can say, okay, this is a curl command, or okay, no, this is just uh something, something, something.
00:40:28.800 --> 00:40:31.760
Now, why it's still private, I don't know.
00:40:32.400 --> 00:40:35.599
Why is that still private with how prolific click fixes?
00:40:36.400 --> 00:40:45.840
My take is that Apple often first pushes these out private and use them and uses them in internally to kind of I think the term is dog food, kind of test them.
00:40:46.320 --> 00:40:48.639
They're probably their own biggest customer, right?
00:40:49.039 --> 00:40:50.000
Yeah, definitely.
00:40:50.079 --> 00:40:54.320
And so there's definitely some like monopoly concerns here, but I'm not a lawyer.
00:40:54.480 --> 00:41:02.320
But I think usually in springtime, then we often see private endpoint security of undocumented ones then kind of be made public.
00:41:02.480 --> 00:41:08.800
So I would be very surprised if in the next six months we don't see Apple making that uh available.
00:41:09.039 --> 00:41:14.000
Kind of, I guess better late than never, but also yeah, super late.
00:41:14.159 --> 00:41:17.519
I think Apple does have some concerns because you can see the pasteboard.
00:41:17.599 --> 00:41:28.559
And you know, if users are copying and pasting passwords, again, this is this unfortunate intersection of security and privacy where in Apple's mind, privacy wins.
00:41:28.800 --> 00:41:30.400
And again, I I get it.
00:41:30.480 --> 00:41:41.440
And so I think they're maybe a little unsure of like, should we let endpoint security tools be able to see every time the user copies and pastes and not just sees that it happens, sees what is being copied and pasted.
00:41:41.760 --> 00:41:44.639
You know, you can see there's some some valid privacy concerns there.
00:41:44.800 --> 00:42:01.119
But I'm hoping that uh in the next six months or so that endpoint security event is made public, which would allow security tools to, I think, comprehensively, maybe not comprehensively, but really provide a very powerful detection and even prevention mechanism.
00:42:01.199 --> 00:42:10.239
Because again, if it's an off authentication event, or sorry, an authorization event, the operating system will actually block the event until the security tool approves it.
00:42:10.400 --> 00:42:12.000
So that would be amazing.
00:42:12.159 --> 00:42:21.920
It would put a huge dent into exactly what you said, the infection vector that the vast, vast majority of stealers are using to target macOS users.
00:42:22.480 --> 00:42:28.559
Yeah, so there should always be more leeway for the security tools I've ever had.
00:42:29.360 --> 00:42:31.440
I agree, but yeah.
00:42:32.000 --> 00:42:34.000
I mean it really should.
00:42:34.480 --> 00:42:41.199
Not to go on a rant, but first and foremost, as I've said a few times, privacy trumps security in Apple Apple world, Apple's world.
00:42:41.280 --> 00:42:45.360
And again, most people really think that they're very aligned, but oftentimes they they definitely deviate.
00:42:45.679 --> 00:42:52.800
Also, you know, for the longest time, Apple really did not think third-party security tools were needed.
00:42:52.960 --> 00:42:58.000
They really believe that the security mechanisms that they build into the operating system are sufficient.
00:42:58.239 --> 00:43:09.599
When they introduced endpoint security, it was such an incredible uh capability that they basically gave to third-party tool developers.
00:43:09.760 --> 00:43:22.320
But more interestingly, at least in my point, in to me, it was them acquiescing and basically saying, hey, yeah, we realize that there is room and need uh for third-party security tools on macOS.
00:43:22.400 --> 00:43:24.239
Before they like didn't even acknowledge that.
00:43:24.400 --> 00:43:28.079
Uh and so, yeah, to your point, security tools should win.
00:43:29.199 --> 00:43:30.480
We have come a long way.
00:43:30.639 --> 00:43:34.159
So I always as soon as I I always have to remind myself of that.
00:43:34.320 --> 00:43:55.199
Um But yeah, uh, I agree 100% with your point that we are still handcuffed in certain scenarios, kind of like with the dialed stuff we're talking about, or currently the fact that we can't access that clipboard event that's sitting there in endpoint security that would literally solve this attack vector that are that is impacting Mac users around the world.
00:43:55.440 --> 00:43:57.840
It's like, come on, Apple, like we're all on the same side here.
00:43:58.000 --> 00:43:59.840
But I promised I wouldn't go on a rant, but.
00:44:00.079 --> 00:44:00.239
Yeah.
00:44:00.719 --> 00:44:03.920
Well imagine marketing of it from them.
00:44:04.079 --> 00:44:08.159
Even if they if they release it, like you be the hero, you you can market it.
00:44:08.239 --> 00:44:11.679
Like you you could say that, but I don't think they're that they're much worried about it.
00:44:11.760 --> 00:44:12.239
About Mudget.
00:44:13.039 --> 00:44:16.639
No, but but again, they've Mudget Glass Wing, that was such great.
00:44:16.800 --> 00:44:18.239
That was a great campaign.
00:44:18.559 --> 00:44:19.039
Oh, I agree.
00:44:19.119 --> 00:44:19.360
100%.
00:44:20.239 --> 00:44:20.800
Yeah.
00:44:21.280 --> 00:44:28.159
The problem is with Apple, anytime you talk about security, they have to acknowledge that what they're doing is not enough.
00:44:28.320 --> 00:44:30.239
And Apple security is incredible.
00:44:30.400 --> 00:44:32.880
I mean, like, I love my iPhone.
00:44:32.960 --> 00:44:37.119
Like, it's compared to any other consumer device, it's arguably the most secure.
00:44:37.760 --> 00:44:43.360
And so like Apple should be nothing but lauded for their security efforts, but they're never going to be perfect.
00:44:43.599 --> 00:44:48.159
And yeah, I think Apple sometimes has a hard time admitting that.
00:44:48.320 --> 00:45:06.239
And so, yeah, they don't like marketing their the tools they give other security products because in a way it's them admitting that they couldn't solve it themselves, which is very difficult for hubris.
00:45:06.639 --> 00:45:14.159
I mean, I think that's why also, too, you you have you have such an amazing community around objective by the state, because they don't do that on like Microsoft.
00:45:14.239 --> 00:45:21.599
They have the Mystic and they've got Patch Tuesday, and they're very involved in the security community versus versus like them.
00:45:21.760 --> 00:45:27.280
No, it that like all the macOS security community is you led by you, you're leading the movement.
00:45:27.360 --> 00:45:29.679
Like it's they want nothing to do with it.
00:45:30.400 --> 00:45:34.239
Which is crazy because I'm like Apple, yo, like we're all on the same side.
00:45:34.400 --> 00:45:37.440
Like, yes, sometimes my approaches are a little different.
00:45:37.519 --> 00:45:44.719
And I always kind of tell this story because once I had a difference of opinion on a feature that Apple had introduced, that I was like, this is right for you.
00:45:46.079 --> 00:45:50.800
No, but I reported to the security team, and the security team was like, yeah, we agree.
00:45:50.880 --> 00:45:55.760
We raise the same concern, but the engineers, Apple Proper, said, we don't see the problem.
00:45:56.000 --> 00:46:03.199
So the security team was like, Patrick, go make some noise about this because the only thing that's gonna change Apple's sway on this is if they get some bad press.
00:46:03.360 --> 00:46:07.920
And so I always give this advice to people, and it's like harsh but true.
00:46:08.000 --> 00:46:14.000
It's like, if you want to get Apple to change their way, the number one way to do that is by getting them bad press.
00:46:14.159 --> 00:46:22.239
And sure enough, as soon as the media picked up on this and was like, wow, there's this like bypass that undermines all these security mechanisms, it's a sign decision by Apple.
00:46:22.400 --> 00:46:26.559
The very next version of Mac OS, they totally rescinded their approach.
00:46:26.880 --> 00:46:30.000
But again, the internal security team was like, they're not listening to us.
00:46:30.079 --> 00:46:31.519
I was like, oh my goodness.
00:46:31.599 --> 00:46:33.679
So it's like, go to the press and make noise.
00:46:33.840 --> 00:46:39.039
Uh and so, yeah, I I do wish Apple would be a little bit more involved.
00:46:39.199 --> 00:46:40.639
They're definitely better than they used to be.
00:46:40.800 --> 00:46:42.880
I have amazing friends that work at Apple.
00:46:43.119 --> 00:46:46.000
I incredibly respect their talent and capabilities.
00:46:46.079 --> 00:46:58.320
But at the cultural level, they really don't, I think, understand the value of a security community that is on the same side, which is how do we protect Mac users and Apple users around the world?
00:46:58.400 --> 00:47:00.079
And that can be frustrating.
00:47:00.320 --> 00:47:04.960
But that also makes us be able to build a great community and have a great conference in Hawaii.
00:47:05.119 --> 00:47:06.719
So, you know, trade-offs.
00:47:07.039 --> 00:47:10.639
I was gonna say, I I am super excited about this.
00:47:10.800 --> 00:47:12.960
The largest Apple security conference, by the way.
00:47:13.119 --> 00:47:15.119
The only one.
00:47:15.760 --> 00:47:17.039
I think so too, yeah.
00:47:17.440 --> 00:47:20.239
What is on the schedule for Objective by the C?
00:47:20.639 --> 00:47:22.639
What are you the most excited about?
00:47:22.800 --> 00:47:26.960
I mean, I know uh last year you had an incredible lineup of Blue Team content.
00:47:27.199 --> 00:47:30.800
Is there, are we, is, is that still kind of like the distribution?
00:47:31.039 --> 00:47:34.159
I'm really interested in like IO like iOS stuff.
00:47:34.480 --> 00:47:37.920
Uh if there's any resources or folks for us to follow.
00:47:38.159 --> 00:47:42.480
Apparently, a lot of my customers in retail too are asking a lot about this.
00:47:42.880 --> 00:47:43.440
Oh, wow.
00:47:43.519 --> 00:47:46.400
Well, first and foremost, they are all invited to the conference.
00:47:46.559 --> 00:47:49.360
So yeah, so I'm the co-founder of the Objective C Foundation.
00:47:49.519 --> 00:47:56.159
And one of the main things we do is organize Objective by the C, which is an annual Apple security conference.
00:47:56.320 --> 00:48:02.800
Uh, this year it's gonna be um in the US, in Hawaii, in the second week of November.
00:48:02.960 --> 00:48:04.079
Yeah, in Maui.
00:48:04.480 --> 00:48:13.760
And it's just a great opportunity because one, the community just gathers there and it's just amazing for connecting, recruiting, meeting, chatting.
00:48:13.840 --> 00:48:15.760
It's like, oh, I just love the vibe about that.
00:48:15.920 --> 00:48:19.760
And then since you asked about the talks, it's I'm really excited about the lineup.
00:48:19.920 --> 00:48:28.079
And I say this every year, but you know, I think it was two or three years ago we actually expanded to three days of talks because there were so many good ones.
00:48:28.239 --> 00:48:35.039
And I get so excited, and I try to jam them into two days, and there were like two super long days, and everyone's like, Patrick, my brain hurts.
00:48:35.119 --> 00:48:36.960
We need to spread this out into three.
00:48:37.119 --> 00:48:42.320
So again, this year we have uh three days, and what I love is there's kind of something for everyone.
00:48:42.400 --> 00:48:46.559
So, first, the great thing is every talk is about Apple security.
00:48:46.639 --> 00:48:51.840
And so, if you're interested in that, there's not gonna be a single talk that's boring to you, which I personally love.
00:48:52.000 --> 00:48:58.719
I go to some of these other conferences, and there's usually just a handful of talks that I like or of interest to me.
00:48:58.960 --> 00:49:02.960
And so there's one track, it's small, so you can approach the speakers afterwards.
00:49:03.119 --> 00:49:06.159
And in terms of topics, there's kind of something for everybody.
00:49:06.320 --> 00:49:08.800
I know that's a little cliche, but let me explain.
00:49:09.039 --> 00:49:17.760
What I realized early on is the most interesting conference talks are the ones where the attendees actually learn something, which in retrospect is super obvious.
00:49:17.920 --> 00:49:21.679
People go to a conference, it's not to be like wowed by some great exploit.
00:49:21.840 --> 00:49:23.199
Okay, that can be interesting.
00:49:23.360 --> 00:49:33.679
But no, if they learn and actually leave with actionable takeaways, that to me, I think are those are the talks that the attendees get most stoked about.
00:49:33.920 --> 00:49:37.199
So we have, I would say, more intro-friendly talks.
00:49:37.280 --> 00:49:53.360
We have some super advanced kernel talks, we have iOS forensics talks, iOS app reversing talks, we have malware talks, we have a bunch of really interesting AI-related talks, again in the context of Apple security.
00:49:53.519 --> 00:49:56.159
And so really the list goes on and on.
00:49:56.320 --> 00:50:14.960
It was very challenging for the committee to select all the talks, but I think they did a really good job highlighting a very disparate kind of group from tool development, exploit development, uh, vulnerability discovery, malware reverse engineering, threat hunting, literally like all the things.
00:50:15.039 --> 00:50:18.639
Uh and so, you know, it's like what's my favorite talk?
00:50:18.800 --> 00:50:19.360
Hard to say.
00:50:19.440 --> 00:50:23.599
There is a talk about dialebs that I'm not one not not my talk.
00:50:23.679 --> 00:50:36.639
Uh there's a talk by another researcher, and they were able to, at least reading their abstract, use trusted signed Apple libraries to basically do all sorts of bad things.
00:50:36.719 --> 00:50:38.400
Um, so I'm actually really excited about their talk.
00:50:38.480 --> 00:50:40.719
Because that was a uh an attack vector I had pondered.
00:50:40.880 --> 00:50:43.599
I never dug into it.
00:50:43.679 --> 00:50:49.039
And I these individuals are definitely smarter than me, so it's great that they ran with with it.
00:50:49.199 --> 00:50:53.360
Uh but yeah, there's just a ton of all sorts of really interesting talks.
00:50:53.519 --> 00:51:05.360
So if you're interested in you know anything from detection, threat hunting, malware, exploits, forensics, iOS, macOS, developing tools, reverse engineering, like there's gonna be talks uh for for everyone.
00:51:05.440 --> 00:51:07.119
And so super, super excited.
00:51:07.199 --> 00:51:12.719
Uh so again, you can go to objectivebythec.org or objective-c dot org to learn more about the conference.
00:51:12.880 --> 00:51:13.840
Second week in November.
00:51:14.000 --> 00:51:16.239
There's also three days of training prior to that.
00:51:16.320 --> 00:51:18.159
Uh, you mentioned Jared Bradley earlier.
00:51:18.239 --> 00:51:19.840
He's doing a threat hunting training.
00:51:20.000 --> 00:51:30.000
We have some iOS trainings, iOS reversing, iOS malware and analysis, looking at some of the zero-click vulnerabilities and the payloads there.
00:51:30.400 --> 00:51:37.599
We have again chemo, open AI, getting a training of kind of using AI to do Apple security stuff.
00:51:37.920 --> 00:51:46.800
So if any of the attendees or listeners here are interested in, you know, trainings, we have three days of awesome trainings and then three days of awesome talks again in Hawaii.
00:51:46.960 --> 00:51:48.239
So check it out.
00:51:48.320 --> 00:51:51.199
And what if we can't want to spend there isn't Hawaii?
00:51:52.000 --> 00:51:52.239
Exactly.
00:51:52.559 --> 00:51:56.320
When you said it went from two to three days, no, no one was mad.
00:51:57.199 --> 00:52:05.760
No, and it's what's what's crazy is like I remember one of the first years, Sarah Edwards, uh, she does iOS forensics now at iVerify.
00:52:05.840 --> 00:52:07.280
She gave a great talk, and it was on the first day.
00:52:07.360 --> 00:52:10.400
And I was like, Sarah, I was like, You're done, you can go hang out by the pool if you want.
00:52:10.639 --> 00:52:12.400
Like, you've earned your vacation.
00:52:12.639 --> 00:52:15.599
And because usually when I talk at conferences, I'm like, okay, I'm done.
00:52:15.679 --> 00:52:16.239
I'm out of here.
00:52:16.480 --> 00:52:19.199
I need to like take a nap or go eat some ice cream or something.
00:52:19.360 --> 00:52:23.039
And I remember she's like, Patrick, she's like, I'm so excited about all the rest of the talk.
00:52:23.119 --> 00:52:24.400
She's like, I'm not going anywhere.
00:52:24.559 --> 00:52:25.920
And I was like, hell yeah.
00:52:26.239 --> 00:52:31.119
So it's really neat, and I really think that speaks to the quality of our speakers and uh talks.
00:52:31.199 --> 00:52:33.840
But yeah, going to three days, nobody complained.
00:52:34.079 --> 00:52:35.119
The days aren't too long.
00:52:35.199 --> 00:52:36.320
We have nice breaks.
00:52:36.400 --> 00:52:43.119
Uh but yeah, just it being the only Apple security conference, we get just top-tier researchers.
00:52:43.360 --> 00:52:53.360
Apple does show up and recruits a decent percentage of them, which initially I was kind of butthurt about because I was like, cool guys, show up and steal them all.
00:52:53.679 --> 00:52:57.760
But it's obviously amazing career opportunities for those individuals.
00:52:57.840 --> 00:53:00.559
And then it really opens the door for new speakers.
00:53:00.719 --> 00:53:07.519
So that's something that we're very passionate about, too, is new speakers, you know, come and you know, for example, Sydney.
00:53:08.480 --> 00:53:10.320
Right, really excited about her talk.
00:53:10.400 --> 00:53:13.519
She was a kind of one of our student scholars last year.
00:53:13.599 --> 00:53:15.199
Uh we have a student scholarship program.
00:53:15.280 --> 00:53:18.480
So also, if you're listening, if you're a student, definitely apply.
00:53:18.639 --> 00:53:24.320
You know, if you're selected, it covers flights, hotels, conference tickets, so like a free week in Hawaii.
00:53:24.400 --> 00:53:25.840
You're like, oh my goodness.
00:53:26.079 --> 00:53:28.000
So Sydney was previously a student scholar.
00:53:28.079 --> 00:53:29.599
Now she's presenting on the main stage.
00:53:29.760 --> 00:53:34.800
So seeing that that um evolution to me is super inspiring.
00:53:34.960 --> 00:53:39.039
And I love that the conference just gives people the platform for them to shine.
00:53:39.199 --> 00:53:43.519
And like that to me is like, ah, it's like gives me all the good feels.
00:53:45.199 --> 00:53:46.559
The Sydney for sure.
00:53:46.719 --> 00:53:51.039
I know she's been she's been very excited about that workshop.
00:53:51.360 --> 00:53:52.800
Stokes, stokes, stokes.
00:53:52.880 --> 00:53:58.400
And maybe we can do uh, you know, uh a podcast recording um uh probably call the thing.
00:53:58.480 --> 00:54:01.039
I was gonna say a live stream.
00:54:01.679 --> 00:54:03.519
Actually use the stream feature.
00:54:04.159 --> 00:54:04.880
Stream, stream.
00:54:05.280 --> 00:54:05.679
The red button.
00:54:09.199 --> 00:54:11.760
Uh well, yeah.
00:54:11.920 --> 00:54:15.519
Now I'm gonna we really have to scheme with with Damien.
00:54:17.119 --> 00:54:20.480
He could like he could hop on and you know yeah.
00:54:20.800 --> 00:54:25.360
Yeah, he could totally especially in November in in uh Chicago.
00:54:25.440 --> 00:54:30.239
I imagine the weather's already starting to it's starting to get pretty fresh.
00:54:30.320 --> 00:54:40.400
Uh November is I I will say I we've got death, the detection engineering and threat hunting uh conference in November, the 12th and the 13th.
00:54:41.039 --> 00:54:42.079
And we we did.
00:54:42.159 --> 00:54:45.039
We stole we stole Jaron Bradley over for that one.
00:54:45.280 --> 00:54:45.760
Hell yeah.
00:54:46.000 --> 00:54:52.719
So we're a bit of we're doing a little bit of double dipping, but yeah, no sick lineups, sick lineup.
00:54:52.880 --> 00:54:55.199
We're super excited about about that for you all.
00:54:55.519 --> 00:54:56.159
Oh, thank you.
00:54:56.239 --> 00:55:03.039
No, we're just very fortunate to have so many incredible speakers that submit such a great community that shows up for the conference.
00:55:03.599 --> 00:55:11.039
Yeah, I mean, we do deserve some credit for organizing the event, but it's not a conference without speakers, and it's obviously not a conference without attendees.
00:55:11.119 --> 00:55:14.079
So it's definitely something that we're kind of all in together.
00:55:14.159 --> 00:55:19.360
So it's always really great when you know people show uh, you know, people come and they're really excited about it.
00:55:19.519 --> 00:55:22.400
Um yeah, like Jaren who's doing a training and then doing a talk.
00:55:22.480 --> 00:55:28.000
And so I think he's probably going to uh your event, your conference, and immediately after jumping on a plane.
00:55:28.239 --> 00:55:32.239
So maybe, maybe, you know, yeah, maybe you can steal his seat.
00:55:32.480 --> 00:55:34.079
No, no, we need him too.
00:55:34.639 --> 00:55:36.079
No, you know, y'all need him.
00:55:36.239 --> 00:55:37.039
He's important.
00:55:37.840 --> 00:55:39.119
He's an he's an OG.
00:55:39.199 --> 00:55:40.559
He's uh he always gives amazing stuff.
00:55:40.880 --> 00:55:42.000
He really he really is.
00:55:42.079 --> 00:55:46.000
That that Sprite tree is something I still I still pick up often.
00:55:46.400 --> 00:56:01.119
Ah, yeah, he's he's talked, I think at most of the conferences, he's just you know, in the threat hunting space, the books he's written, uh I mean I learned a ton from them because that's really he he explains complex things in a very simple way.
00:56:01.360 --> 00:56:06.079
But also, I'm not traditionally a threat hunter, so a lot of the stuff he talks about is super interesting.
00:56:06.159 --> 00:56:09.840
And I love because many of his talks he then releases tools as well.
00:56:10.000 --> 00:56:14.880
And that's really awesome because it's something that then you know you can read the code, play with.
00:56:15.280 --> 00:56:15.599
Super cool.
00:56:15.679 --> 00:56:16.639
So yeah, we love Jan.
00:56:16.800 --> 00:56:17.280
He rocks.
00:56:17.440 --> 00:56:20.480
And again, he's just an example of of someone in the community.
00:56:20.559 --> 00:56:23.199
Uh, and there's many people like them, super giving.
00:56:23.280 --> 00:56:30.639
You know, his training, he always like keeps some open seats for the students we select, so as all as our as all our trainers do.
00:56:30.719 --> 00:56:36.639
So again, just like really good, amazing community vibes at the at the conference that we are super appreciative of.
00:56:37.119 --> 00:56:41.599
And so it's just an incredible event that yeah, we hope to see you there as well.
00:56:42.159 --> 00:56:44.800
Yes, I'm gonna try my very hardest to go.
00:56:44.960 --> 00:56:48.880
And because that's exactly what this whole entire thing is all about.
00:56:48.960 --> 00:56:49.840
It's community.
00:56:50.079 --> 00:56:53.039
So thank you so, so much, Patrick, for your time.
00:56:53.119 --> 00:56:58.719
And for literally this this evening, I saw it go from like light to dark over over there by you.
00:57:01.440 --> 00:57:03.360
My friends are like, what are you doing on Friday evening?
00:57:03.440 --> 00:57:05.039
And I'm like, I'm recording a podcast.
00:57:05.199 --> 00:57:06.639
Y'all should be super jealous.
00:57:07.280 --> 00:57:07.840
I know.
00:57:08.000 --> 00:57:10.400
I will let you go get your Friday night started.
00:57:10.639 --> 00:57:17.599
I mean, I although I know that in Spain things don't get things don't really like y'all don't really start going out until like 9, 10 p.m., no?
00:57:18.079 --> 00:57:18.800
Yeah, exactly.
00:57:18.880 --> 00:57:22.079
So it's 8:30 right now, and dinner's at 10.
00:57:22.159 --> 00:57:24.800
So this is like this is still technically the afternoon.
00:57:24.880 --> 00:57:25.840
So we're all good here.
00:57:26.079 --> 00:57:27.760
But no, Alex, thank you so much.
00:57:28.079 --> 00:57:33.840
I love talking about these topics, and so I really appreciate you inviting me onto the podcast.
00:57:34.000 --> 00:57:39.840
And I think nothing else is after the conference, we could probably chat more because there's gonna be a ton of really cool content.
00:57:39.920 --> 00:57:41.679
Uh but yeah, we'll we'll scheme.
00:57:41.760 --> 00:57:49.920
And again, thank you so much for for having me on here and uh listening to me rant and ramble and hopefully drop some valuable tips about it.
00:57:50.079 --> 00:57:52.000
Oh, you've dropped you've dropped all the right things.
00:57:52.480 --> 00:57:53.760
I I really appreciate it.
00:57:53.840 --> 00:58:05.760
I I think the biggest takeaway is we're we're really good at detecting, you know, where where we are comfortable looking and versus the blind spots that we've already decided to trust.
00:58:06.079 --> 00:58:17.039
So thank you so much for and I love that you articulated that because you know, as you said a few times, the adversaries and attackers continue to evolve.
00:58:17.119 --> 00:58:22.960
And it's easy for us to get rest on our orals, stuck in our ruts, whatever the phrases are, and so exactly.
00:58:23.039 --> 00:58:25.199
And sometimes we have our biases and blind spots.
00:58:25.280 --> 00:58:35.840
And so with agents running on boxes, with dial-ups now being a more interesting attack surface, the adversaries are going to evolve and change because they also are looking for our blind spot.
00:58:35.920 --> 00:58:42.159
So it's great that we can talk about this because once we've identified where we're not looking and our blind spots, we can then address that.
00:58:42.239 --> 00:58:44.400
And I think we're gonna start to uncover some really cool stuff.
00:58:44.639 --> 00:58:47.519
Maybe scary stuff, but I always think it's cool.
00:58:49.360 --> 00:58:52.719
Well, uh I'm looking forward for the highlights.
00:58:52.800 --> 00:58:56.960
Uh, if we you always are invited back to Detection Dispatch, Patrick.
00:58:57.679 --> 00:59:03.360
Hopefully, we can keep the conversation going about what continues to traject in the macOS uh landscape.
00:59:03.599 --> 00:59:05.599
This has been the episode of Detection Dispatch.
00:59:05.760 --> 00:59:09.199
Keep hunting, keep questioning, and we'll see you next time.