A deep dive into the techniques in the macOS framework
While there is a significantly higher number of Windows users than macOS users, there are still over 100 million macOS users and macOS endpoints are growing in popularity, especially in the private business sector and specifically for tech companies. Overall, the difference in size means that there are fewer attacks that are targeted at macOS endpoints, but that certainly doesn’t mean that there are none. Additionally, it’s important to note that there are a significant number of techniques and sub-techniques that are different between the macOS and Windows matrices due to how the base OS works and how the filesystems are set up. If anything, macOS aligns more closely with the Linux OS. Similarly to the Windows section, we’ll dig into a few different techniques and sub-techniques:
- Initial Access
- Drive-by Compromise, Exploit Public Facing Application, External Remote Services, Hardware Additions, Phishing...