• caglararli@hotmail.com
  • 05386281520

Adding custom rules to apple xprotect

Çağlar Arlı      -    13 Views

Adding custom rules to apple xprotect

I'm trying to build an endpoint protection software on MacOS, apart from ESF or OpenBSM, I need to block and detect malicious softwares.

I found xprotect to be useful,

But I'm not sure whether I can add custom yara rules. It looks so wrong to modify the sqlite3 database. Is there any official ways to do that?