Olivia Gallucci ✨
@OliviaGalluccii
Followers
6K
Following
3K
Media
207
Statuses
1K
Security @ Datadog | MacOS Internals | #FOSS Advocate | Opinions ≠ Employer | @intelligentCTF @oghealthfitness | RIT | Prev. Apple, SECUINFRA, US Govt
Just moved to NYC!
Joined April 2020
I'm thrilled to announce I'll be starting a monthly publication: [ret]2read -- An OS Internals Newsletter! 🍎⚙️ Each month, I'll discuss something I'm working on (like designing a kernel fuzzer for macOS 👀), and how I am applying different techniques, tools, and research to my
11
49
250
Apple released a new XProtect update this week. I don't know how many changes I've tracked, but it's a lot. If you want to see the history of the XProtect yara updates (which rules have changed, added, removed), I have them all here. https://t.co/iksmOZVQeS
notes.crashsecurity.io
0
9
32
NEW macOS 26.0 🥫🍝 sauce! 🎉 xnu: https://t.co/d1DjJsStqx dyld: https://t.co/iKYiWSpxcV objc4: https://t.co/Kvp9wWc8lU Security: https://t.co/IqmyOIcvsE Libsystem: https://t.co/JflpfJ49II Libc: https://t.co/eLTMJ2n2tJ - this post was generated by `ipsw` 🤖
2
21
101
🎙️ Why talk about "AI Employees" instead of agents? Maybe the paradigm of employee feedback and performance management is the future of agent observability and evaluation... On our latest episode of Deployed we talk with @surojit, founder of @Ema_Unlimited, about his lessons
2
0
11
Back home after an incredible time at #OBTS! Was inspiring meeting incredible people and experiencing the beautiful island of Ibiza. A huge thanks to @patrickwardle and @andyrozen for having me :)
0
2
22
GIVEAWAY TIME! 🍎♥️🤘 In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza 🇪🇸 @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
3
9
44
How does your chat with ChatGPT usually end? It doesn’t — you just stop typing. But therapy works differently. Closure matters. In Mira, every session has a beginning, a process, and an end. It closes with a Coping Card — a short summary of your key insights and tools to help
1
5
20
We love it when American Airlines cancels your flights and doesn’t reschedule you lol
5
0
17
Does anyone else just drink hot water, or is that weird?
9
1
12
🔔 Push Alert: SPL💥ITLIGHT just landed live. A cheeky Spotlight plugin slid past TCC (CVE-2025-31199), giving the search bar a backstage pass into Apple Intelligence — DB peeks, sensitive queries, even odd multi-user cross-talk. On stage: Christine Fossaceca @x71n3 (@Microsoft
0
3
7
I have two numbers for you... $53 billion and $450 billion. That's $53 billion straight to the bottom line of Big Insurance with zero benefit to taxpayers. Some would call that fraud. And that's $450 billion more from your pockets if the Biden COVID credits are extended.
6
5
56
Christine @x71n3 and JBO (@yo_yo_yo_jbo ) (& Alexia Wilson) from @Microsoft showed #OBTS how Spotlight just got too bright. 😬 They found a macOS TCC bypass (#CVE-2025-31199) that abuses Spotlight to get your private data - locally and remotely - and showed how to detect!
1
7
21
Sal (@malwarezoo) from @jamf gave an excellent talk at #OBTS of how Apple tracks and revokes malicious apps. But Revoked doesn’t always mean Vanquished! Sal found a Gatekeeper/CDHash weakness that brings blocked apps back to life — no re-signing required. #CVE-2025-43296
0
8
21
It is time to look at another great talk from the 2025 BSides312 event. In this one, Olivia Gallucci talks about unlocking MacOS internals. They explain it form a standpoint of breaking down Apple's open source ecosystem. #BSides #BSides312 #MacOS
https://t.co/XCVU5K8xs6
0
4
12
A new paper about SPTM, TXM and Exclaves has been released. It might be a good introductory read for the DeepDive into SPTM, TXM, SK and Exclaves training later this year.
antid0te-sg.com
There is a party at GLx and you have been invited. Antid0te is organising an online deep dive into SPTM, TXM, SK and Exclaves Training in December 2025 and January 2026. Instructor: Stefan Esser (
Awesome paper about latest iOS security mitigations : SPTM, TXM, and Exclaves https://t.co/EXcHTigw3M
0
6
33
Watch the talk here: https://t.co/0Pee5JJf4R
#OBTS
Olivia (@oliviagalluccii) from @datadoghq entertained #OBTS, showing us how macOS logs everything, diving into ULS, ESF, and TCC.db to hunt threats like Atomic Stealer & XCSSET, and using tools like Consolation3, eslogger, Mac Monitor to catch evil!
2
20
106
Olivia (@oliviagalluccii) from @datadoghq entertained #OBTS, showing us how macOS logs everything, diving into ULS, ESF, and TCC.db to hunt threats like Atomic Stealer & XCSSET, and using tools like Consolation3, eslogger, Mac Monitor to catch evil!
2
7
35
In a nutshell: Create tradable AI agents in less than 1min, with the x402 protocol embedded in their autonomous pipeline. Enabling them to transact with other fellow agents or with humans. A powerful addition to the most powerful agent creation flow in the space.
3
10
32
Penultimate talk of #OBTS day 2 by @OliviaGalluccii on using ES & Unified Log to understand and detect malware
1
3
8
📖 man macOS-internals(1) — threat detection for humans Olivia Gallucci @OliviaGalluccii | #OBTS 🍏 NAME Logs, ESF & automation risks — what attackers touch, what defenders can see. CORE ULS + ESF + TCC.db = where the truth lives (and lies try to hide). TOOLS Consolation3,
0
3
16
🧾 AFTER-TALK COMMIT — macOS Internals for Threat Detection Engineers Author: Olivia Gallucci @OliviaGalluccii | #OBTS 🍏 •logs: ULS turned from diary → deposition 🔍 •ESF: follow fork→exec with eslogger / ESFPlayground (no firehose) •TCC.db: consent vs. reality mapped
0
3
11
Behind the scenes at #OBTS Lots of great questions, insightful discussions, and that unique sense of community you only find here. Huge thanks to @patrickwardle for bringing together such an inspiring crowd! 🙌 #Moonlock #ObjectiveByTheSea
0
3
11