macos-internals

Installation
SKILL.md

macOS Internals — detection-relevant knowledge

This skill encodes how macOS works at the level needed to write detections for macOS endpoints. macOS has fundamentally different security architecture from Windows and Linux — detections cannot be ported without understanding these differences.


1. Process model

Process creation

macOS uses posix_spawn() (preferred) or fork()/exec() for process creation. Key differences from Windows:

Concept macOS Windows equivalent Detection relevance
launchd (PID 1) Init system, manages all services SCM + Task Scheduler Parent of all system services. Unexpected launchd children are suspicious.
XPC services Inter-process communication framework COM/DCOM Sandboxed helper processes. XPC service abuse = privilege escalation.
App bundles .app directories with Info.plist .exe files Malware can hide in app bundle resources
Universal binaries Fat binaries with multiple architectures N/A Can contain both x86_64 and arm64 code
Rosetta 2 x86_64 translation on Apple Silicon WoW64 x86_64 processes on arm64 hardware — unusual for native apps
Installs
3
First Seen
Sep 16, 2026