macos-internals
Installation
SKILL.md
macOS Internals — detection-relevant knowledge
This skill encodes how macOS works at the level needed to write detections for macOS endpoints. macOS has fundamentally different security architecture from Windows and Linux — detections cannot be ported without understanding these differences.
1. Process model
Process creation
macOS uses posix_spawn() (preferred) or fork()/exec() for process creation. Key differences from Windows:
| Concept | macOS | Windows equivalent | Detection relevance |
|---|---|---|---|
| launchd (PID 1) | Init system, manages all services | SCM + Task Scheduler | Parent of all system services. Unexpected launchd children are suspicious. |
| XPC services | Inter-process communication framework | COM/DCOM | Sandboxed helper processes. XPC service abuse = privilege escalation. |
| App bundles | .app directories with Info.plist |
.exe files |
Malware can hide in app bundle resources |
| Universal binaries | Fat binaries with multiple architectures | N/A | Can contain both x86_64 and arm64 code |
| Rosetta 2 | x86_64 translation on Apple Silicon | WoW64 | x86_64 processes on arm64 hardware — unusual for native apps |