Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
macOS-Security-and-Privacy-Guide — Curated macOS security and privacy guide with practical instructions for threat modeling, disk encryption, firewall configuration, secure authentication, and network hardening. | Kitploit
Outils/GitHubGitHub/drduh/macos-security-and-privacy-guide
Network SecurityWireless SecurityCryptographyPrivacyAuthenticationLearning & EducationCurated Resources
GitHubdrduh/macos-security-and-privacy-guide

macOS-Security-and-Privacy-Guide

Curated macOS security and privacy guide with practical instructions for threat modeling, disk encryption, firewall configuration, secure authentication, and network hardening.

Voir le dépôtSite web
22.5k1.5k135il y a 12 joursVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

This guide is a collection of techniques for improving the security and privacy of macOS on Apple silicon Macs. It targets experienced users who want security practices commonly used by organizations, but is also suitable for novice users with an interest in privacy and security.

For organization-managed Macs, see the macOS Security Compliance Project, maintained by the U.S. National Institute of Standards and Technology.

This guide is provided "as is" - without warranties of any kind. You are solely responsible for any consequences of following it.

  • Basics
  • Threat model
    • Assets
    • Adversaries
    • Capabilities
    • Mitigations
    • Example model
  • Hardware
  • Installing macOS
    • System activation
    • Apple Account
    • App Store
    • Virtualization
      • Apple containers
  • First boot
  • Admin and user accounts
    • Caveats
    • Setup
  • Firmware
  • FileVault
  • Lockdown Mode
  • Firewall
    • Application layer firewall
      • Stealth mode
      • Signed apps
      • Reload firewall
      • Get state
      • AirDrop
    • Third-party firewalls
    • Packet filter
      • Example pf config
      • Firewall commands
      • Block networks
  • Services
  • Siri Suggestions and Spotlight
  • Homebrew
  • DNS
    • DNS profiles
    • Hosts file
    • DNSCrypt
    • Dnsmasq
  • Certificate authorities
  • Privoxy
  • Browser
    • Firefox
    • Chrome
    • Safari
    • Web browser privacy
  • Tor
  • VPN
    • WireGuard
  • PGP/GPG
  • Email
    • Thunderbird
  • Messengers
    • XMPP
    • Signal
    • iMessage
  • Malware
    • Downloading Software
    • App Sandbox
    • Hardened Runtime
    • Antivirus
    • Gatekeeper
  • System Integrity Protection
  • Metadata and artifacts
  • Authentication
  • Backup
  • Wi-Fi
  • SSH
  • Physical access
  • Monitoring
    • Logs
    • DTrace
    • Processes
    • Endpoint Security
    • Install History
    • Network
      • Wireshark
  • Miscellaneous
    • Screensaver
    • Diagnostic data
    • Media player
    • File handlers
    • Finder options
    • Custom umask
    • Keyboard entry
    • Network hardening
    • Sudoers
  • Related software
  • Additional resources

Basics

Apply general security best practices:

  • Create a threat model

    • Is your adversary a local eavesdropper, a criminal using common malware, or a well-funded and highly capable organization?
    • Define the threats or groups you are defending against and what they can realistically do.
  • Keep the system and software up to date

    • Regularly install available updates for the operating system and all applications.
    • Updates are installed in System Settings or with the softwareupdate command-line utility. Neither requires an Apple Account.
    • Subscribe to the Apple security-announce mailing list or check Apple security releases.
  • Encrypt sensitive data

    • Enable FileVault to encrypt internal storage.
    • Use a password manager for account credentials and consider encrypting especially sensitive files separately.
  • Ensure data availability

    • Create regular backups of critical data and be ready to restore from a backup in case of compromise.
    • Encrypt backups before copying them to external media or third-party cloud storage. Alternatively, use a backup service that provides end-to-end encryption.
    • Verify backups by accessing them on a regular, scheduled basis.
  • Click carefully

    • Ultimately, the security of a system depends heavily on the capabilities and habits of the person using and administering it.
    • Take care when installing new software: install it only from sources the developer identifies as official, such as their website or GitHub repository.

Threat model

The most important step to meaningfully improve security and privacy is to create a threat model: a general description of what you want to protect, who might try to access it, how they could do so, and which controls are worth usability trade-offs. This creates an understanding of potential adversaries and their motivations, which leads to stronger defenses.

Assets

Assets may include a phone, laptop, credentials, and personal information, such as browsing history.

List them in order of importance, starting with those most worth protecting.

Adversaries

Define whom you are defending against. Start by defining the motivation each adversary might have to attack important assets. Financial gain is a big motivator for many attackers, for example.

Capabilities

For each adversary, list what they can and cannot do, ranking them from least to most capable. For example, a casual thief operates opportunistically: they will likely be defeated by basic controls, such as screen lock and encrypted storage with strong passwords. A more sophisticated and determined adversary may require fully powering off a device when not in use to clear credentials from memory and stronger authentication mechanisms.

Mitigations

Choose the best mitigation for each threat. For example, avoid writing passwords on paper if a roommate might find them, or encrypt storage to protect its data if it is stolen.

Security should be balanced with usability: every mitigation should counter some adversarial capability to justify any inconvenience. Stop adding defenses when the remaining risks are acceptable for a situation. Revisit the model when devices, data, travel, work, or adversaries change.

Example model

The following table is a simple example threat model for personal devices, including a Mac.

Télécharger l’outil