Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

How to track or analyze plist drift or changes on OSX?

How to track or analyze plist drift or changes on OSX?

Version:

v7.0.x


Topic:
The solution explains how track or analyze the changes made to plist files on OSX?


Answer:

The Bit9 Agent does not analyze or track plist drift/ changes out of the box. This is because it does not treat plist files as 'interesting' content.

To monitor and report changes on the plist file(s) a Custom Report rule can be added through the Bit9 Console:

- Navigate to Rules --> Software Rules --> Custom 

- Click on Add Custom Rule and fill in the rule details.

Name and Description: Free text

Status should be: Enabled

Rule Type will be: File Integrity Rule

Write Action will be: Report.

In the Path or File indicate the plist files(s) you would like to track.

You may also select toe exclude specific processes from this rule.

Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-05-2015
Views:
466
Contributors