Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
macos_xprotect — Apple의 내장 악성코드 보호 기능에 대한 교육적 심층 분석: 서명 데이터베이스, YARA 규칙, Gatekeeper 통합, 복구 바이너리 및 macOS 탐지 흐름. | Kitploit
도구/GitHubGitHub/yo-yo-yo-jbo/macos_xprotect
Defensive ToolsMalware AnalysisBinary AnalysisLearning & Education
GitHubyo-yo-yo-jbo/macos_xprotect

macos_xprotect

Apple의 내장 악성코드 보호 기능에 대한 교육적 심층 분석: 서명 데이터베이스, YARA 규칙, Gatekeeper 통합, 복구 바이너리 및 macOS 탐지 흐름.

저장소 보기
31112개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

macOS - XProtect 소개

macOS 소개 블로그 포스트 시리즈에 이어서, XProtect에 관한 짧은 블로그 포스트를 작성하기로 했습니다.

XProtect란 무엇인가?

XProtect는 Apple이 macOS에 내장한 안티바이러스 및 악성코드 시그니처 시스템입니다.
XProtectService의 일부로 작동하며, 알려진 악성코드 시그니처가 있는지 애플리케이션 및 기타 실행 콘텐츠를 검사합니다.
XProtect는 백그라운드에서 작동하며 Apple이 XProtectRemediator 메커니즘을 통해 자동으로 업데이트합니다(자세한 내용은 나중에 설명).
다음과 같은 3가지 주요 기능이 있습니다:

  • 시그니처 기반 탐지 – 알려진 악성코드 시그니처 데이터베이스를 기준으로 파일을 검사합니다.
  • 행동 기반 탐지(XProtect Remediator) – macOS Monterey에서 도입되었으며, 정적 시그니처뿐만 아니라 의심스러운 행동을 기반으로 XProtect가 악성코드를 선제적으로 검사하고 제거할 수 있게 합니다.
  • 실시간 차단 – XProtect는 알려진 악성 소프트웨어가 실행되기 전에 실행을 차단합니다.

기존 XProtect

/Library/Apple/System/Library/CoreServices/XProtect.bundle 디렉터리는 XProtect 구성과 시그니처 정의가 포함된 기본 번들입니다.
읽기 전용 시스템 디렉터리이며 Apple이 XProtect 업데이트를 통해 자동으로 업데이트합니다.
그 아래에는 흥미로운 파일 몇 개가 있는데, 모두 Apple이 주기적으로 업데이트하며 시스템 무결성 보호(SIP)로 보호됩니다.

XProtect.plist

/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist 파일에는 XProtect가 알려진 위협을 탐지하는 데 사용하는 악성코드 시그니처가 저장되어 있습니다.
이 파일에는 해시와 파일명 패턴을 포함하여 악성코드 패밀리를 특정 탐지 규칙에 매핑하는 항목이 포함되어 있습니다.
다음은 한 악성코드 패밀리인 Bundalore의 예시입니다:

<dict>
        <key>Description</key>
        <string>OSX.Bundlore.D</string>
        <key>LaunchServices</key>
        <dict>
                <key>LSItemContentType</key>
                <string>com.apple.application-bundle</string>
        </dict>
        <key>Matches</key>
        <array>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>46617364554153</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>20006500630068006F002000</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
                </dict>
        </array>
</dict>

이 표현은 꽤 읽기 쉬운 편이며, 주목할 만한 유일한 부분은 각 매치의 string 인자가 16진수 표현이라는 점입니다. 예를 들어 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073는 -salt -A -a -d | bash -s에 해당합니다.
물론 이는 정확히 어떤 패턴을 피해야 하는지 알 수 있는, 악성코드 작성자에게는 금광과 같은 정보입니다.

XProtect.meta.plist

/Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist 파일은 적용 정책과 버전 정보를 포함하여 XProtect에 대한 추가 규칙을 정의하는 메타데이터 파일입니다.
특정 XProtect 규칙을 적용하는 macOS 버전, 탐지 시 수행되는 조치, 그리고 플러그인 블랙리스트를 지정합니다.
다음은 예시입니다:

<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
        <key>10</key>
        <dict>
                <key>com.apple.java.JavaAppletPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>14.8.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.apple.java.JavaPlugin2_NPAPI</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>14.8.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.macromedia.Flash Player ESR.plugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>18.0.0.382</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.macromedia.Flash Player.plugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>32.0.0.101</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.microsoft.SilverlightPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>5.1.41212.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.oracle.java.JavaAppletPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>1.8.51.16</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
        </dict>
</dict>

보시다시피, 여기에는 예를 들어 "블랙리스트에 등재된" 플러그인에 대한 버전 정보가 포함되어 있습니다.

XProtect.yara

최근 버전에서 XProtect는 YARA를 지원하기 시작한 것으로 보입니다.
/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara 파일에는 텍스트 형식의 여러 YARA 규칙이 포함되어 있습니다. 그중 짧은 예시는 다음과 같습니다:

rule XProtect_MACOS_SLEEPYSTEGOSAURUS_SYM {
    meta:
        description = "MACOS.SLEEPYSTEGOSAURUS.SYM"
        uuid = "BB4F7D16-C939-4047-A9AF-E74E7B51FAC1"
    strings:
        $a1 = { 45 78 65 63 43 6D 64 }
        $a2 = { 47 65 74 48 6F 73 74 49 6E 66 6F }
        $a3 = { 52 75 6E 53 63 72 69 70 74 }
        $a4 = { 52 75 6E 53 63 72 69 70 74 55 72 6C }
        $a5 = { 4C 61 75 6E 63 68 50 6C 69 73 74 }
        $a6 = { 43 68 65 63 6B 50 72 6F 63 65 73 73 }
        $a7 = { 43 68 65 63 6B 49 6E }
        $a8 = { 52 75 6E 43 6D 64 46 69 6C 65 }
        $a9 = { 53 68 6F 77 48 74 6D 6C }
        $a10 = { 50 6C 69 73 74 48 65 6C 70 65 72 }
        $a11 = { 4C 61 75 6E 63 68 64 48 65 6C 70 65 72 }
        $a12 = { 43 6F 6D 6D 61 6E 64 46 69 6C 65 }
        $a13 = { 57 72 69 74 65 50 6C 69 73 74 }
        $a14 = { 4A 53 4F 4E 46 69 6C 65 50 72 6F 63 65 73 73 6F 72 }
        $a15 = { 43 68 72 6F 6D 65 48 65 6C 70 65 72 }
        $a16 = { 53 61 6E 64 62 6F 78 65 72 }
    condition:
        Macho and filesize < 2MB and all of them
}

이 글은 YARA 규칙에 관한 블로그 포스트는 아니지만, 앞서 말한 대로 이는 악성코드 작성자에게 금광과 같은 정보입니다 (예: 43 68 65 63 6B 50 72 6F 63 65 73 73는 CheckProcess).

gk.db

도구 다운로드