
Summary
The rule 'Unsupported macOS version' is designed to ensure that all laptops within a corporate environment run on macOS versions that are supported by IT. This is critical for maintaining security and compliance as outdated operating systems may expose systems to vulnerabilities and potential attacks. The rule achieves this by checking the macOS version using data collected from the Osquery framework and comparing it against the supported versions specified by IT. If a laptop is found to be running an unsupported version, appropriate actions are prompted, such as upgrading the operating system to a secure and supported version as per the guidelines in the runbook. The implementation of this rule also aids in maintaining compliance with organizational policies regarding software updates and security patches.
Categories
- macOS
- Endpoint
Data Sources
- User Account
- Process
- Logon Session
- Container
ATT&CK Techniques
- T2012
Created: 2022-09-02