

Apple, Please Give Us More Logs feat. Patrick Wardle
Patrick Wardle joins Detection Dispatch to explore what happens when the things we trust become the things we stop looking at. From signed and notarized applications hiding malicious dylibs to trusted processes inheriting privileges, Patrick walks through the places where macOS can look completely clean until you look underneath it. We get into dynamic library hijacking, the limitations of process level telemetry, and the detection opportunities hiding inside macOS Endpoint Security. We also explore ClickFix, rogue AI agents, and the increasingly difficult question of how to distinguish malicious behavior from legitimate activity when attackers or autonomous agents are operating through trusted software. In this episode we get into: • Why dynamic library hijacking is still alive on macOS despite years of Apple mitigations • How the 3CX supply chain attack hid malicious code inside a trusted application that was signed, notarized, and largely overlooked by security tooling • Why attackers love dylibs: stealth, inherited trust, and inherited privileges • The problem with treating the process as the atomic unit of detection when malicious code can execute inside a trusted process • Why enumerating loaded libraries on macOS is surprisingly difficult and the Endpoint Security workarounds that make it possible • How process, file, and network events can be stitched together to reveal behavior that individual events do not show • Why code signing is incredibly useful for macOS detection and why “signed” does not mean “safe” • How AI agents executing legitimate platform binaries make attribution even harder: is the behavior malicious, anomalous, user directed, or the result of a compromised agent? • Why ClickFix and clipboard to terminal execution have become such an effective macOS delivery mechanism • The huge detection opportunity hiding inside an undocumented Endpoint Security clipboard event • What makes Objective by the Sea different and why building a strong Apple security community matters just as much as the research Objective by the Sea: https://objectivebythesea.com/ Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.
- Transcript












