EDR Internals for macOS and Linux | Outflank Security Blog
Many public blogs and conference talks have covered Windows telemetry sources like kernel callbacks and ETW, but few mention macOS and Linux equivalents. Although most security professionals may not be surprised by this lack of coverage, one should not overlook these platforms. For example, developers using macOS often have privileged cloud accounts or access to intellectual property like source code. Linux servers may host sensitive databases or customer-facing applications. Defenders must have confidence in their tools for these systems, and attackers must understand how to evade them. This post dives into endpoint security products on macOS and Linux to understand their capabilities and identify weaknesses. Endpoint detection and response (EDR) agents comprise multiple sensors: components that collect events from one or more telemetry sources. The agent formats raw telemetry data into a standard format and then forwards it to a log aggregator. EDR telemetry data informs tools such a
Many public blogs and conference talks have covered Windows telemetry sources like kernel callbacks and ETW, but few mention macOS and Linux equivalents. Although most security professionals may not be surprised by this lack of coverage, one should not overlook these platforms. For example, developers using macOS often have privileged cloud accounts or access to intellectual property like source code. Linux servers may host sensitive databases or customer-facing applications. Defenders must have confidence in their tools for these systems, and attackers must understand how to evade them.…
saved by
related reading
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Empowering Threat Detection With Custom Detections in EDRtruesec.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Report: The Era of Endpoints | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Battling macOS Malware with Cortex AI - Palo Alto Networks Blogpaloaltonetworks.com
- All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more - Tristan Humethume.ca
- Security incident disclosure — July 2026huggingface.co
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org
- Why Endpoint Security Tools Are Still Such a Challengedatabreachtoday.com
- Apple Platform Securityhelp.apple.com
- When the hunter becomes the hunted: Using custom callbacks to disable EDRsalteredsecurity.com