Jaron Bradley
@jbradley89
Followers
3K
Following
720
Media
49
Statuses
493
MacOS Intrusion Analyst, APT Smiter , Haole. Author of OS X Incident Response Scripting and Analysis Owner of https://t.co/oApHpiRaQ0
Hilo, HI
Joined March 2014
I picked up a copy of @jbradley89’s new “Threat Hunting macOS” book at #OBTS. Opened it up to Section 12 on Passwords and immediately learned something new
Incase you missed it, I dropped my new book “Threat Hunting macOS” last month. You can purchase it from my website if you’re interested! https://t.co/wOlMwj3NkU
0
1
16
Incase you missed it, I dropped my new book “Threat Hunting macOS” last month. You can purchase it from my website if you’re interested! https://t.co/wOlMwj3NkU
themittenmac.com
https://youtu.be/OnIAmOz0TjoChapter 1https://youtu.be/9bQCWbe2kDwChapter 2Now Available in the U.S.Welcome to my latest book. Threat Hunting macOS—a book that share
0
5
31
The printed copies of my new book have arrived and will be shipping mid October. Here is a first look! Pre orders still available at https://t.co/BV5MX9C6Jc
2
2
26
Checkout our blog post on “ChillyHell”. A modular backdoor for macOS that was signed and notarized by a threat actor tracked as UNC4487. https://t.co/eYFfik2h0o
jamf.com
Discover its origin, how it compromises macOS and more importantly, how the JTL detected this malicious threat to keep Jamf customers safe.
0
5
22
Had a great time discussing my upcoming book with @davisrichardg at @13CubedDFIR. Richard is a pleasure to talk to and a true technology wizard. Check out his trainings for macOS forensics! Books still available for pre-order at themittenmac website https://t.co/A9y7As9QK5
0
3
22
My next book is open for pre-orders!!! I have included the first two chapters in audiobook form for free. You can listen to them now on my website or you can listen and read the sample on Apple Books. Looking forward to getting it into your hands. https://t.co/wOlMwj4las
themittenmac.com
https://youtu.be/OnIAmOz0TjoChapter 1https://youtu.be/9bQCWbe2kDwChapter 2Now Available in the U.S.Welcome to my latest book. Threat Hunting macOS—a book that share
2
32
135
Santa delivered my brand new book: “The Art of Mac Malware Vol II: Detecting Malicious Software” 🍎🛡️🐛👨🏻💻📚🥰 Three years in the making(!) this 2nd volume in the TAOMM series covers the heuristic-based detection of macOS malware Buy direct via @nostarch: https://t.co/M7Da6k59Vk
12
94
425
I’m working on a new book Thank you to all those who told me my first book has helped them in the macOS world in some way This book focuses on the internals necessary to build detections and perform analysis of intrusions on macOS Any shares to help measure interest helps!
17
97
399
Join me at 3:00ish pm HST to see some fun machO research. Lots of amazing talks before and after too!
Today is the day! #OBTS 🤩 Join us live: https://t.co/mF4MHZ98Gc
0
2
23
Today we released a blog post detailing how threat actors are using the Flutter Engine to build malware for macOS. This results in a very complex app architecture that is difficult to reverse. Check out the details here... https://t.co/joP4RJgL7D
jamf.com
With malicious code hidden within, the new malware with ties to DPRK, has evaded detection by notable malware checking systems that may signal a new way of attacking macOS devices.
1
42
131
My bug CVE-2024-44131 got patched on iOS 18.0. It’s an iOS TCC bypass bug that lets third-party apps access data stored on iCloud Drive. I’ll be sharing the technical details, along with demo screenshots of leaking (encrypted) WhatsApp backup data, on the Jamf Blog.
8
38
263
I finished Snake&Apple VIII, an introduction to #Apple #App #Sandbox on #macOS. Inside, you will find info about kernel extension and how Sandbox Profiles are enforced to mitigate the risks of successful macOS #malware #infection. https://t.co/7vbA0Sngwu Enjoy reading! 👨💻
karol-mazurek.medium.com
Introduction to the App Sandbox on macOS with Python
0
17
57
The FBI recently sent a warning out regarding DPRK activity against the crypto industry. Today, we documented attacks we've seen on macOS. Attacks start with social engineering and deliver a piece of malware that we call ThiefBucket. https://t.co/9QbC9OoCXn
#malware
jamf.com
FBI released a PSA set to warn those in the crypto industry that the DPRK has been targeting individuals by using clever social engineering techniques. Read more.
3
43
127
This was very good last year, @jbradley89 is an excellent trainer
@Helthydriver @naehrdine Jaron Bradley's (@jbradley89) training, "Threat Hunting macOS" provides an in-depth and hands experience, for those looking for a deep dive into using macOS internals to their advantage for threat hunting! 🔎🍎🖥️ More info/to sign up: https://t.co/BR0jibrZIS
0
3
13
Honored to speak on the makers track at #FTSCon with some of these great presenters
We have another speaker to announce in our #FTSCon lineup: Jaron Bradley (@jbradley89) will present “Grafting Trees on macOS” in the MAKER Track! For event details, see the #FTSCon event page: https://t.co/xfDn513usL You can also register here: https://t.co/8ee3K4JFus
#dfir
0
3
17
Some awesome Gatekeeper vulnerability research from @malwarezoo that lead to the discovery of vulnerabilities in other products. Check it out on our blog when you get time.
Our latest research details a Gatekeeper bug we reported to Apple that affects Launch Services. While exploring this issue, we also found ways to bypass Gatekeeper using the “The Unarchiver”, a popular archiving application on macOS. Check out our blog: https://t.co/VBNm92uJCu
0
0
13
TrueTree 0.8 is out. Its primary difference is that when displaying the tree , it will attempt to use other pids only if the parent process of that given process id is launchd. You also now have the ability to display only the process name with --nopath https://t.co/8wMqU282CO
0
9
27