jbradley89 Profile Banner
Jaron Bradley Profile
Jaron Bradley

@jbradley89

Followers
3K
Following
720
Media
49
Statuses
493

MacOS Intrusion Analyst, APT Smiter , Haole. Author of OS X Incident Response Scripting and Analysis Owner of https://t.co/oApHpiRaQ0

Hilo, HI
Joined March 2014
Don't wanna be here? Send us removal request.
@0xmachos
mikey
4 days
I picked up a copy of @jbradley89’s new “Threat Hunting macOS” book at #OBTS. Opened it up to Section 12 on Passwords and immediately learned something new
@jbradley89
Jaron Bradley
5 days
Incase you missed it, I dropped my new book “Threat Hunting macOS” last month. You can purchase it from my website if you’re interested! https://t.co/wOlMwj3NkU
0
1
16
@jbradley89
Jaron Bradley
5 days
Incase you missed it, I dropped my new book “Threat Hunting macOS” last month. You can purchase it from my website if you’re interested! https://t.co/wOlMwj3NkU
Tweet card summary image
themittenmac.com
https://youtu.be/OnIAmOz0TjoChapter 1https://youtu.be/9bQCWbe2kDwChapter 2Now Available in the U.S.Welcome to my latest book. Threat Hunting macOS—a book that share
0
5
31
@arinwaichulis
Arin Waichulis
7 days
My new read just arrived! Thanks for the copy @jbradley89 and congrats on the second book.
1
3
10
@jbradley89
Jaron Bradley
1 month
The printed copies of my new book have arrived and will be shipping mid October. Here is a first look! Pre orders still available at https://t.co/BV5MX9C6Jc
2
2
26
@jbradley89
Jaron Bradley
2 months
Checkout our blog post on “ChillyHell”. A modular backdoor for macOS that was signed and notarized by a threat actor tracked as UNC4487. https://t.co/eYFfik2h0o
Tweet card summary image
jamf.com
Discover its origin, how it compromises macOS and more importantly, how the JTL detected this malicious threat to keep Jamf customers safe.
0
5
22
@jbradley89
Jaron Bradley
3 months
Had a great time discussing my upcoming book with @davisrichardg at @13CubedDFIR. Richard is a pleasure to talk to and a true technology wizard. Check out his trainings for macOS forensics! Books still available for pre-order at themittenmac website https://t.co/A9y7As9QK5
0
3
22
@jbradley89
Jaron Bradley
5 months
My next book is open for pre-orders!!! I have included the first two chapters in audiobook form for free. You can listen to them now on my website or you can listen and read the sample on Apple Books. Looking forward to getting it into your hands. https://t.co/wOlMwj4las
Tweet card summary image
themittenmac.com
https://youtu.be/OnIAmOz0TjoChapter 1https://youtu.be/9bQCWbe2kDwChapter 2Now Available in the U.S.Welcome to my latest book. Threat Hunting macOS—a book that share
2
32
135
@patrickwardle
Patrick Wardle
11 months
Santa delivered my brand new book: “The Art of Mac Malware Vol II: Detecting Malicious Software” 🍎🛡️🐛👨🏻‍💻📚🥰 Three years in the making(!) this 2nd volume in the TAOMM series covers the heuristic-based detection of macOS malware Buy direct via @nostarch: https://t.co/M7Da6k59Vk
12
94
425
@jbradley89
Jaron Bradley
11 months
I’m working on a new book Thank you to all those who told me my first book has helped them in the macOS world in some way This book focuses on the internals necessary to build detections and perform analysis of intrusions on macOS Any shares to help measure interest helps!
17
97
399
@jbradley89
Jaron Bradley
11 months
Join me at 3:00ish pm HST to see some fun machO research. Lots of amazing talks before and after too!
@objective_see
Objective-See Foundation
11 months
Today is the day! #OBTS 🤩 Join us live: https://t.co/mF4MHZ98Gc
0
2
23
@jbradley89
Jaron Bradley
1 year
Today we released a blog post detailing how threat actors are using the Flutter Engine to build malware for macOS. This results in a very complex app architecture that is difficult to reverse. Check out the details here... https://t.co/joP4RJgL7D
Tweet card summary image
jamf.com
With malicious code hidden within, the new malware with ties to DPRK, has evaded detection by notable malware checking systems that may signal a new way of attacking macOS devices.
1
42
131
@08Tc3wBB
Huke
1 year
My bug CVE-2024-44131 got patched on iOS 18.0. It’s an iOS TCC bypass bug that lets third-party apps access data stored on iCloud Drive. I’ll be sharing the technical details, along with demo screenshots of leaking (encrypted) WhatsApp backup data, on the Jamf Blog.
8
38
263
@karmaz95
Karol Mazurek
1 year
I finished Snake&Apple VIII, an introduction to #Apple #App #Sandbox on #macOS. Inside, you will find info about kernel extension and how Sandbox Profiles are enforced to mitigate the risks of successful macOS #malware #infection. https://t.co/7vbA0Sngwu Enjoy reading! 👨‍💻
karol-mazurek.medium.com
Introduction to the App Sandbox on macOS with Python
0
17
57
@jbradley89
Jaron Bradley
1 year
The FBI recently sent a warning out regarding DPRK activity against the crypto industry. Today, we documented attacks we've seen on macOS. Attacks start with social engineering and deliver a piece of malware that we call ThiefBucket. https://t.co/9QbC9OoCXn #malware
Tweet card summary image
jamf.com
FBI released a PSA set to warn those in the crypto industry that the DPRK has been targeting individuals by using clever social engineering techniques. Read more.
3
43
127
@0xmachos
mikey
1 year
This was very good last year, @jbradley89 is an excellent trainer
@objective_see
Objective-See Foundation
1 year
@Helthydriver @naehrdine Jaron Bradley's (@jbradley89) training, "Threat Hunting macOS" provides an in-depth and hands experience, for those looking for a deep dive into using macOS internals to their advantage for threat hunting! 🔎🍎🖥️ More info/to sign up: https://t.co/BR0jibrZIS
0
3
13
@jbradley89
Jaron Bradley
1 year
Honored to speak on the makers track at #FTSCon with some of these great presenters
@volatility
volatility
1 year
We have another speaker to announce in our #FTSCon lineup: Jaron Bradley (@jbradley89) will present “Grafting Trees on macOS” in the MAKER Track! For event details, see the #FTSCon event page: https://t.co/xfDn513usL You can also register here: https://t.co/8ee3K4JFus #dfir
0
3
17
@jbradley89
Jaron Bradley
1 year
Some awesome Gatekeeper vulnerability research from @malwarezoo that lead to the discovery of vulnerabilities in other products. Check it out on our blog when you get time.
@malwarezoo
Ferdous Saljooki
1 year
Our latest research details a Gatekeeper bug we reported to Apple that affects Launch Services. While exploring this issue, we also found ways to bypass Gatekeeper using the “The Unarchiver”, a popular archiving application on macOS. Check out our blog: https://t.co/VBNm92uJCu
0
0
13
@jbradley89
Jaron Bradley
1 year
TrueTree 0.8 is out. Its primary difference is that when displaying the tree , it will attempt to use other pids only if the parent process of that given process id is launchd. You also now have the ability to display only the process name with --nopath https://t.co/8wMqU282CO
0
9
27