
ISC StormCast for Friday, November 18th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
How to Detect a User Double Clicking to Open an Application
I looked at two different things. One I looked at Apple's unified log system. The other one I looked at the Apple Endpoint Security Framework event messages. If there was any difference between a user double clicking to open an application versus right clicking to opening an application, I didn't find anything in either case. So that was how I, using that what I found in the unified log is in my research papers how I described how you can actually build a detection. Yeah, and I basically just ingest that into your seam and can write rules around it to basically alert a user.
Transcript
Play full episode