Serious Discussion BlockBlock by Objective-See for Mac (v2.1.5 - November 2022)

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,318
2
55,055
8,379
Malware installs itself persistently to ensure it's automatically (re)executed. BlockBlock monitors common persistence locations and alerts whenever a persistent component is added.

Though BlockBlock is conceptually simple, it is a rather complex piece of software. BlockBlock is made up of three main components, a kernel extension, a user-mode daemon running as root, and a user-mode agent running as the logged-in user (there can be multiple such agents if BlockBlock is installed for several users on the same system).
 
  • Like
Reactions: Fritz
Been using it for quite a while now and can recommend it. Runs smoothly and reports changes immediately.