OliviaGalluccii Profile Banner
Olivia Gallucci ✨ Profile
Olivia Gallucci ✨

@OliviaGalluccii

Followers
6K
Following
3K
Media
207
Statuses
1K

Security @ Datadog | MacOS Internals  | #FOSS Advocate | Opinions ≠ Employer | @intelligentCTF @oghealthfitness | RIT | Prev. Apple, SECUINFRA, US Govt

Just moved to NYC!
Joined April 2020
Don't wanna be here? Send us removal request.
@OliviaGalluccii
Olivia Gallucci ✨
2 months
I'm thrilled to announce I'll be starting a monthly publication: [ret]2read -- An OS Internals Newsletter! 🍎⚙️ Each month, I'll discuss something I'm working on (like designing a kernel fuzzer for macOS 👀), and how I am applying different techniques, tools, and research to my
11
49
250
@stuartjash
Stuart Ashenbrenner 🇺🇸 🇨🇦
2 days
Apple released a new XProtect update this week. I don't know how many changes I've tracked, but it's a lot. If you want to see the history of the XProtect yara updates (which rules have changed, added, removed), I have them all here. https://t.co/iksmOZVQeS
Tweet card summary image
notes.crashsecurity.io
0
9
32
@blacktop__
Blacktop
3 days
NEW macOS 26.0 🥫🍝 sauce! 🎉 xnu: https://t.co/d1DjJsStqx dyld: https://t.co/iKYiWSpxcV objc4: https://t.co/Kvp9wWc8lU Security: https://t.co/IqmyOIcvsE Libsystem: https://t.co/JflpfJ49II Libc: https://t.co/eLTMJ2n2tJ - this post was generated by `ipsw` 🤖
2
21
101
@freeplay_ai
Freeplay
14 hours
🎙️ Why talk about "AI Employees" instead of agents? Maybe the paradigm of employee feedback and performance management is the future of agent observability and evaluation... On our latest episode of Deployed we talk with @surojit, founder of @Ema_Unlimited, about his lessons
2
0
11
@objective_see
Objective-See Foundation
4 days
The #OBTS community is simply incredible!! 😍 From trainers & speakers to students & attendees, you made this the best #OBTS yet 🙏🏽 Photos, recordings & slides coming soon!
1
10
37
@dillon_franke
Dillon Franke
3 days
Back home after an incredible time at #OBTS! Was inspiring meeting incredible people and experiencing the beautiful island of Ibiza. A huge thanks to @patrickwardle and @andyrozen for having me :)
0
2
22
@g0njxa
Who said what?
6 days
GIVEAWAY TIME! 🍎♥️🤘 In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza 🇪🇸 @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
3
9
44
@gbmolch
G.B. Molcher
5 days
How does your chat with ChatGPT usually end? It doesn’t — you just stop typing. But therapy works differently. Closure matters. In Mira, every session has a beginning, a process, and an end. It closes with a Coping Card — a short summary of your key insights and tools to help
1
5
20
@OliviaGalluccii
Olivia Gallucci ✨
7 days
We love it when American Airlines cancels your flights and doesn’t reschedule you lol
5
0
17
@OliviaGalluccii
Olivia Gallucci ✨
7 days
Imperative research!
@OliviaGalluccii
Olivia Gallucci ✨
7 days
Does anyone else just drink hot water, or is that weird?
2
0
5
@OliviaGalluccii
Olivia Gallucci ✨
7 days
Does anyone else just drink hot water, or is that weird?
9
1
12
@Mu55sy
Mussy
8 days
🔔 Push Alert: SPL💥ITLIGHT just landed live. A cheeky Spotlight plugin slid past TCC (CVE-2025-31199), giving the search bar a backstage pass into Apple Intelligence — DB peeks, sensitive queries, even odd multi-user cross-talk. On stage: Christine Fossaceca @x71n3 (@Microsoft
0
3
7
@TarrenBragdon
Tarren Bragdon
15 hours
I have two numbers for you... $53 billion and $450 billion. That's $53 billion straight to the bottom line of Big Insurance with zero benefit to taxpayers. Some would call that fraud. And that's $450 billion more from your pockets if the Biden COVID credits are extended.
6
5
56
@forensicdave
Doc Dave
8 days
Christine @x71n3 and JBO (@yo_yo_yo_jbo ) (& Alexia Wilson) from @Microsoft showed #OBTS how Spotlight just got too bright. 😬 They found a macOS TCC bypass (#CVE-2025-31199) that abuses Spotlight to get your private data - locally and remotely - and showed how to detect!
1
7
21
@forensicdave
Doc Dave
8 days
Sal (@malwarezoo) from @jamf gave an excellent talk at #OBTS of how Apple tracks and revokes malicious apps. But Revoked doesn’t always mean Vanquished! Sal found a Gatekeeper/CDHash weakness that brings blocked apps back to life — no re-signing required. #CVE-2025-43296
0
8
21
@bsides312
BSides312
9 days
It is time to look at another great talk from the 2025 BSides312 event. In this one, Olivia Gallucci talks about unlocking MacOS internals. They explain it form a standpoint of breaking down Apple's open source ecosystem. #BSides #BSides312 #MacOS https://t.co/XCVU5K8xs6
0
4
12
@i0n1c
Stefan Esser
9 days
A new paper about SPTM, TXM and Exclaves has been released. It might be a good introductory read for the DeepDive into SPTM, TXM, SK and Exclaves training later this year.
Tweet card summary image
antid0te-sg.com
There is a party at GLx and you have been invited. Antid0te is organising an online deep dive into SPTM, TXM, SK and Exclaves Training in December 2025 and January 2026. Instructor: Stefan Esser (
@matteyeux
matteyeux
11 days
Awesome paper about latest iOS security mitigations : SPTM, TXM, and Exclaves https://t.co/EXcHTigw3M
0
6
33
@Mu55sy
Mussy
9 days
🍹 Day 2 — Evening wrap (six talks, brains buzzing) #OBTS 🍏 – 🧪 Beyond Static Labels — behavior-first grayware: deception • persistence • monetization • consent • payload; Adload (2016–2025) proves stickers lie, behavior tells. Rousana Charles – 🧭 Who Cares Where Waldo Is
0
4
13
@OliviaGalluccii
Olivia Gallucci ✨
9 days
Watch the talk here: https://t.co/0Pee5JJf4R #OBTS
@forensicdave
Doc Dave
9 days
Olivia (@oliviagalluccii) from @datadoghq entertained #OBTS, showing us how macOS logs everything, diving into ULS, ESF, and TCC.db to hunt threats like Atomic Stealer & XCSSET, and using tools like Consolation3, eslogger, Mac Monitor to catch evil!
2
20
106
@forensicdave
Doc Dave
9 days
Olivia (@oliviagalluccii) from @datadoghq entertained #OBTS, showing us how macOS logs everything, diving into ULS, ESF, and TCC.db to hunt threats like Atomic Stealer & XCSSET, and using tools like Consolation3, eslogger, Mac Monitor to catch evil!
2
7
35
@Orbofi
Orbofi
16 hours
In a nutshell: Create tradable AI agents in less than 1min, with the x402 protocol embedded in their autonomous pipeline. Enabling them to transact with other fellow agents or with humans. A powerful addition to the most powerful agent creation flow in the space.
3
10
32
@0xmachos
mikey
9 days
Penultimate talk of #OBTS day 2 by @OliviaGalluccii on using ES & Unified Log to understand and detect malware
1
3
8
@Mu55sy
Mussy
9 days
📖 man macOS-internals(1) — threat detection for humans Olivia Gallucci @OliviaGalluccii | #OBTS 🍏 NAME Logs, ESF & automation risks — what attackers touch, what defenders can see. CORE ULS + ESF + TCC.db = where the truth lives (and lies try to hide). TOOLS Consolation3,
0
3
16
@Mu55sy
Mussy
9 days
🧾 AFTER-TALK COMMIT — macOS Internals for Threat Detection Engineers Author: Olivia Gallucci @OliviaGalluccii | #OBTS 🍏 •logs: ULS turned from diary → deposition 🔍 •ESF: follow fork→exec with eslogger / ESFPlayground (no firehose) •TCC.db: consent vs. reality mapped
0
3
11
@moonlock_com
Moonlock by MacPaw
9 days
Behind the scenes at #OBTS Lots of great questions, insightful discussions, and that unique sense of community you only find here. Huge thanks to @patrickwardle for bringing together such an inspiring crowd! 🙌 #Moonlock #ObjectiveByTheSea
0
3
11