Process monitoring¶
Technique |
Description |
Tools/Commands |
---|---|---|
ESF (Endpoint Security Framework) |
Apple’s official API for real-time process/event monitoring |
|
XPC Service Analysis |
Detect suspicious inter-process communication |
|
Mach-O Binary Inspection |
Check for unsigned/hooked binaries |
|
Last update:
2025-05-12 14:39