Open in app

Sign In

Write

Sign In

Cedric Owens
Cedric Owens

403 Followers

Home

About

May 25, 2022

Taking ESF For A(nother) Spin

2+ years ago from the date of this blog post I wrote my initial blog post where I started becoming familiar with Apple’s Endpoint Security Framework (ESF) on macOS and seeing what different macOS post exploitation activities looked like through the lens of ESF (link: https://medium.com/red-teaming-with-a-blue-team-mentality/taking-the-macos-endpoint-security-framework-for-a-quick-spin-802a462dba06).

Threat Hunting

8 min read

Taking ESF For A(nother) Spin
Taking ESF For A(nother) Spin
Threat Hunting

8 min read


Feb 26, 2022

Give Me Some (macOS) Context…

This blog post will dive into what I like to call “execution contexts” on macOS and why it is important to understand these different contexts from a red team perspective when operating on macOS endpoints. …

Macos

6 min read

Give Me Some (macOS) Context…
Give Me Some (macOS) Context…
Macos

6 min read


Feb 19, 2022

Querying Spotlight APIs With JXA

TL;DR This blog post takes a brief look at how to use JXA (native JavaScript for Automation on macOS) to query Spotlight APIs. In particular, this post will be looking at how to run mdfind searches in JXA without invoking the on-disk mdfind binary. Why? I enjoy writing scripts/utilities for…

Red Team

5 min read

Querying Spotlight APIs With JXA
Querying Spotlight APIs With JXA
Red Team

5 min read


Oct 30, 2021

“Spotlighting” Your TCC Access Permissions

Note: This is not a TCC Bypass. Instead this is a technique for checking TCC access permissions As an offensive security engineer, one of the things I aim to avoid is quickly burning initial access on a host. On macOS hosts, one of the ways to do this is to…

Red Team

6 min read

“Spotlighting” Your TCC Access Permissions
“Spotlighting” Your TCC Access Permissions
Red Team

6 min read


Aug 3, 2021

“HELK’ing” Your macOS Red Team Tools For Detections

This post builds on content from 4n7m4n’s prior blog post “Acting Red — Seeing Blue” (link). Specifically, I automated HELK server standup using terraform to stand up your HELK server in Digital Ocean with the appropriate specs as well as with firewall rules to protect access to your HELK server…

Red Team

5 min read

“HELK’ing” Your macOS Red Team Tools For Detections
“HELK’ing” Your macOS Red Team Tools For Detections
Red Team

5 min read


Jul 16, 2021

Working Around macOS Privacy Controls in Red Team Ops

This blog post will take a look at some simple basics around what macOS privacy controls (Transparancy, Consent, and Control a.k.a. TCC) are and how red team operations on macOS hosts can still be effective despite these controls. This blog post will not cover any TCC bypasses but will instead…

Red Team

5 min read

Working Around macOS Privacy Controls in Red Team Ops
Working Around macOS Privacy Controls in Red Team Ops
Red Team

5 min read


Jul 11, 2021

Interesting macOS Chrome Browser Files

This blog will take a quick look at Chrome files on macOS that are not protected by TCC and do not require root access to read from. As these files are not protected by TCC, any non-sandboxed macOS payload will be able to access these files without needing TCC permissions. …

Red Team

4 min read

Interesting macOS Chrome Browser Files
Interesting macOS Chrome Browser Files
Red Team

4 min read


May 22, 2021

macOS MS Office Sandbox Brain Dump

This blog will take a look at some observations regarding what is still possible from the MS Office Sandbox on macOS. This is a combination of insight from others as well as some tests that I have attempted. …

Red Team

4 min read

macOS MS Office Sandbox Brain Dump
macOS MS Office Sandbox Brain Dump
Red Team

4 min read


May 3, 2021

CVE-2021–30657 Revisited

This is a quick follow-up to my previous blog where I discussed how I found the bug behind CVE-2021–30657 (link to previous blog, which also contains a link to Patrick Wardle’s deep dive into the bug itself: https://cedowens.medium.com/macos-gatekeeper-bypass-2021-edition-5256a2955508). In this blog post I will share another very basic method that…

Macos

2 min read

CVE-2021–30657 Revisited
CVE-2021–30657 Revisited
Macos

2 min read


Apr 26, 2021

macOS Gatekeeper Bypass (2021 Edition)

This post will briefly discuss how a bug that I uncovered in macOS Catalina 10.15 (specifically tested on 10.15.7) and in macOS Big Sur before Big Sur 11.3 allows an attacker to very easily craft a macOS payload that is not checked by Gatekeeper. This payload can be used in…

Macos

9 min read

macOS Gatekeeper Bypass (2021 Edition)
macOS Gatekeeper Bypass (2021 Edition)
Macos

9 min read

Cedric Owens

Cedric Owens

403 Followers

Red teamer with blue team roots🤓👨🏽‍💻 Twitter: @cedowens

Following
  • Brendan Chamberlain

    Brendan Chamberlain

  • Phillip Wylie: The Hacker Maker

    Phillip Wylie: The Hacker Maker

  • Leo Pitt

    Leo Pitt

  • Andy Robbins

    Andy Robbins

  • Wojciech Reguła

    Wojciech Reguła

See all (34)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech