Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
macos_xprotect — 深入探究 Apple 内置恶意软件防护的教育性内容:签名数据库、YARA 规则、Gatekeeper 集成、修复二进制文件以及 macOS 检测流程。 | Kitploit
工具/GitHubGitHub/yo-yo-yo-jbo/macos_xprotect
防御工具恶意软件分析二进制分析学习与教育
GitHubyo-yo-yo-jbo/macos_xprotect

macos_xprotect

深入探究 Apple 内置恶意软件防护的教育性内容:签名数据库、YARA 规则、Gatekeeper 集成、修复二进制文件以及 macOS 检测流程。

查看仓库
31112个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

macOS 简介 - XProtect

继续我关于 macOS 介绍的博客系列,我决定用一篇简短的博文专门介绍 XProtect。

什么是 XProtect?

XProtect 是 Apple 为 macOS 内置的防病毒和恶意软件签名系统。
它作为 XProtectService 的一部分运行,扫描应用程序和其他可执行内容以查找已知的恶意软件签名。
XProtect 在后台运行,由 Apple 通过 XProtectRemediator 机制静默更新(稍后会详细介绍)。
它有 3 个主要功能:

  • 基于签名的检测——它根据已知恶意软件签名数据库扫描文件。
  • 行为检测(XProtect Remediator)——在 macOS Monterey 中引入,使 XProtect 能够主动扫描并基于可疑行为(而不仅仅是静态签名)移除恶意软件。
  • 实时拦截——XProtect 在已知恶意软件运行之前阻止其执行。

传统 XProtect

目录 /Library/Apple/System/Library/CoreServices/XProtect.bundle 是包含 XProtect 配置和签名定义的主 bundle。
这是一个只读的系统目录,由 Apple 通过 XProtect 更新静默更新。
在其下,我们可以找到一些值得关注的文件,这些文件都由 Apple 定期更新,并受 System Integrity Protection (SIP) 保护。

XProtect.plist

文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist 存储 XProtect 用于检测已知威胁的恶意软件签名。
它包含将恶意软件家族映射到特定检测规则的条目,包括哈希和文件名模式。
以下是其中一个恶意软件家族——Bundalore 的示例:

<dict>
        <key>Description</key>
        <string>OSX.Bundlore.D</string>
        <key>LaunchServices</key>
        <dict>
                <key>LSItemContentType</key>
                <string>com.apple.application-bundle</string>
        </dict>
        <key>Matches</key>
        <array>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>46617364554153</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>20006500630068006F002000</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
                </dict>
                <dict>
                        <key>MatchFile</key>
                        <dict>
                                <key>NSURLTypeIdentifierKey</key>
                                <string>com.apple.applescript.script</string>
                        </dict>
                        <key>MatchType</key>
                        <string>Match</string>
                        <key>Pattern</key>
                        <string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
                </dict>
        </array>
</dict>

这相当易读,唯一值得注意的是每个匹配中的 string 参数是十六进制表示,例如 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073 对应 -salt -A -a -d | bash -s。
当然,这对恶意软件作者来说是一个金矿,因为他们确切知道要避免哪些模式。

XProtect.meta.plist

文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist 是一个元数据文件,为 XProtect 定义附加规则,包括执行策略和版本信息。
它指定了哪些 macOS 版本强制执行某些 XProtect 规则、检测到威胁后采取的操作,以及插件黑名单。
以下是一个示例:

<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
        <key>10</key>
        <dict>
                <key>com.apple.java.JavaAppletPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>14.8.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.apple.java.JavaPlugin2_NPAPI</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>14.8.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.macromedia.Flash Player ESR.plugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>18.0.0.382</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.macromedia.Flash Player.plugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>32.0.0.101</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.microsoft.SilverlightPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>5.1.41212.0</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
                <key>com.oracle.java.JavaAppletPlugin</key>
                <dict>
                        <key>MinimumPlugInBundleVersion</key>
                        <string>1.8.51.16</string>
                        <key>PlugInUpdateAvailable</key>
                        <true/>
                </dict>
        </dict>
</dict>

如你所见,这些包含“黑名单”插件的版本信息,例如。

XProtect.yara

在最近的版本中,XProtect 似乎开始支持 YARA。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara 包含若干文本格式的 YARA 规则,以下是其中的一个简短示例:

rule XProtect_MACOS_SLEEPYSTEGOSAURUS_SYM {
    meta:
        description = "MACOS.SLEEPYSTEGOSAURUS.SYM"
        uuid = "BB4F7D16-C939-4047-A9AF-E74E7B51FAC1"
    strings:
        $a1 = { 45 78 65 63 43 6D 64 }
        $a2 = { 47 65 74 48 6F 73 74 49 6E 66 6F }
        $a3 = { 52 75 6E 53 63 72 69 70 74 }
        $a4 = { 52 75 6E 53 63 72 69 70 74 55 72 6C }
        $a5 = { 4C 61 75 6E 63 68 50 6C 69 73 74 }
        $a6 = { 43 68 65 63 6B 50 72 6F 63 65 73 73 }
        $a7 = { 43 68 65 63 6B 49 6E }
        $a8 = { 52 75 6E 43 6D 64 46 69 6C 65 }
        $a9 = { 53 68 6F 77 48 74 6D 6C }
        $a10 = { 50 6C 69 73 74 48 65 6C 70 65 72 }
        $a11 = { 4C 61 75 6E 63 68 64 48 65 6C 70 65 72 }
        $a12 = { 43 6F 6D 6D 61 6E 64 46 69 6C 65 }
        $a13 = { 57 72 69 74 65 50 6C 69 73 74 }
        $a14 = { 4A 53 4F 4E 46 69 6C 65 50 72 6F 63 65 73 73 6F 72 }
        $a15 = { 43 68 72 6F 6D 65 48 65 6C 70 65 72 }
        $a16 = { 53 61 6E 64 62 6F 78 65 72 }
    condition:
        Macho and filesize < 2MB and all of them
}

这不是一篇关于 YARA 规则的博文,但和之前一样——这对恶意软件作者来说是一个金矿(例如 43 68 65 63 6B 50 72 6F 63 65 73 73 就是 CheckProcess)。

gk.db

在这里你可以看到 Apple 如何设计 XProtect 与 Gatekeeper 集成——尽管这个文件主要供 syspolicyd 使用。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/gk.db 是一个 SQLite 数据库,包含要阻止的文件哈希和团队 ID 的“黑名单”。
你可以使用 sqlite3 实用程序查看它:

下载工具