SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) cover image

ISC StormCast for Friday, November 18th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

00:00

How to Detect a User Double Clicking to Open an Application

I looked at two different things. One I looked at Apple's unified log system. The other one I looked at the Apple Endpoint Security Framework event messages. If there was any difference between a user double clicking to open an application versus right clicking to opening an application, I didn't find anything in either case. So that was how I, using that what I found in the unified log is in my research papers how I described how you can actually build a detection. Yeah, and I basically just ingest that into your seam and can write rules around it to basically alert a user.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app