The Art of Mac Malware, Volume 2
This first-of-its-kind guide to detecting stealthy Mac malware gives you the tools and techniques to counter even the most sophisticated threats targeting the Apple ecosystem.

Macs have become a popular target of cyber-criminals, and there are few effective defenses against these pernicious threats — until now. The second volume of The Art of Mac Malware is the first book to cover state-of-the-art programming techniques and security tools for detecting and countering malicious code running on a macOS system.

Author Patrick Wardle, a former NSA hacker and a leading authority on macOS threat analysis, shares real-world examples from his own research to reveal the many strategies used by actual malware specimens to evade detection. As you dive deep into the Mac operating system’s internals, you’ll learn about:

  • Apple’s public and private frameworks and APIs
  • How to build heuristic-based security tools for the macOS
  • Using the macOS Endpoint Security framework to develop real-time monitoring software
  • Objective-See’s suite of anti-malware tools, including KnockKnock, BlockBlock, and OverSight

But this book is not just aimed at practitioners — for anyone interested in understanding the current threats facing the Apple ecosystem, it’s a must-read.
"1146117577"
The Art of Mac Malware, Volume 2
This first-of-its-kind guide to detecting stealthy Mac malware gives you the tools and techniques to counter even the most sophisticated threats targeting the Apple ecosystem.

Macs have become a popular target of cyber-criminals, and there are few effective defenses against these pernicious threats — until now. The second volume of The Art of Mac Malware is the first book to cover state-of-the-art programming techniques and security tools for detecting and countering malicious code running on a macOS system.

Author Patrick Wardle, a former NSA hacker and a leading authority on macOS threat analysis, shares real-world examples from his own research to reveal the many strategies used by actual malware specimens to evade detection. As you dive deep into the Mac operating system’s internals, you’ll learn about:

  • Apple’s public and private frameworks and APIs
  • How to build heuristic-based security tools for the macOS
  • Using the macOS Endpoint Security framework to develop real-time monitoring software
  • Objective-See’s suite of anti-malware tools, including KnockKnock, BlockBlock, and OverSight

But this book is not just aimed at practitioners — for anyone interested in understanding the current threats facing the Apple ecosystem, it’s a must-read.
49.99 Pre Order
The Art of Mac Malware, Volume 2

The Art of Mac Malware, Volume 2

by Patrick Wardle
The Art of Mac Malware, Volume 2

The Art of Mac Malware, Volume 2

by Patrick Wardle

Paperback

$49.99 
  • SHIP THIS ITEM
    Qualifies for Free Shipping
    Available for Pre-Order. This item will be released on February 25, 2025
  • PICK UP IN STORE

    Store Pickup available after publication date.

Related collections and offers


Overview

This first-of-its-kind guide to detecting stealthy Mac malware gives you the tools and techniques to counter even the most sophisticated threats targeting the Apple ecosystem.

Macs have become a popular target of cyber-criminals, and there are few effective defenses against these pernicious threats — until now. The second volume of The Art of Mac Malware is the first book to cover state-of-the-art programming techniques and security tools for detecting and countering malicious code running on a macOS system.

Author Patrick Wardle, a former NSA hacker and a leading authority on macOS threat analysis, shares real-world examples from his own research to reveal the many strategies used by actual malware specimens to evade detection. As you dive deep into the Mac operating system’s internals, you’ll learn about:

  • Apple’s public and private frameworks and APIs
  • How to build heuristic-based security tools for the macOS
  • Using the macOS Endpoint Security framework to develop real-time monitoring software
  • Objective-See’s suite of anti-malware tools, including KnockKnock, BlockBlock, and OverSight

But this book is not just aimed at practitioners — for anyone interested in understanding the current threats facing the Apple ecosystem, it’s a must-read.

Product Details

ISBN-13: 9781718503786
Publisher: No Starch Press
Publication date: 02/25/2025
Pages: 280
Product dimensions: 7.00(w) x 9.25(h) x (d)

About the Author

Patrick Wardle is the founder of the Objective-See Foundation, DoubleYou.Ai, and the #OBTS conference. Having worked at NASA and the NSA, as well as presented at countless security conferences, he is intimately familiar with aliens, spies, and talking nerdy. Patrick is passionate about all things related to macOS security and thus spends his days finding Apple 0days, writing books on macOS malware, and releasing free open-source security tools to protect Mac users around the world.

Table of Contents

Foreword
Acknowledgments
Introduction

Part I: Data Collection
Chapter 1. Examining Processes
Chapter 2. Parsing Binaries
Chapter 3. Code Signing
Chapter 4. Network State and Statistics
Chapter 5. Persistence

Part II: System Monitoring
Chapter 6. Log Monitoring
Chapter 7. Network Monitoring
Chapter 8. Endpoint Security
Chapter 9: Muting and Authorization Events

Part III: Tool Creation
Chapter 10: Persistence Enumerator
Chapter 11: Persistence Monitor
Chapter 12: Mic and Webcam Monitor
Chapter 13: DNS Monitor
Chapter 14. Case Studies
Index
From the B&N Reads Blog

Customer Reviews