Skip to main content

About

This blog is where I document things I encounter while investigating macOS threats — attacker TTPs, endpoint telemetry, hunting techniques and detection ideas.

Most posts are practical rather than deep malware reverse engineering: what happened, what the telemetry shows, how I investigated it, and what could be detected or hunted.

I try to keep the write-ups straightforward enough that people who are less familiar with macOS can still follow the investigation.