RSSAmplifier

Blog

Olivia A. Gallucci

Offensive Security, Open Source, and Glitter

oliviagallucci.comRSS feed ↗10 posts

Latest posts

iBoot stage (main bootloader) security on macOS

How iBoot on Apple Silicon Macs acts as the final secure gate before macOS launches by verifying signed boot assets, enforcing memory and hardware protections, validating the SSV, and making boot-level compromise significantly harder than attacks against the kernel or user space. The post iBoot stage (main bootloader) security on macOS appeared first on Olivia A. Gallucci .

Low-Level Bootloader (LLB) Security on macOS

Overview of the Apple Silicon Low-Level Bootloader. Explains how LLB verifies firmware, enforcing SEP-signed LocalPolicy and anti-replay. The post Low-Level Bootloader (LLB) Security on macOS appeared first on Olivia A. Gallucci .

macOS EDR Telemetry Project: A Framework for Evaluating Endpoint Visibility

Expansion of the EDR Telemetry Project with the launch of a dedicated macOS telemetry framework and a reproducible telemetry generator. The post macOS EDR Telemetry Project: A Framework for Evaluating Endpoint Visibility appeared first on Olivia A. Gallucci .

Boot ROM Security on Silicon Macs (M1/M2/M3)

A overview of Apple Silicon Boot ROM security. Explains how SecureROM anchors the boot chain of trust, and exploits surrounding it. The post Boot ROM Security on Silicon Macs (M1/M2/M3) appeared first on Olivia A. Gallucci .

Security & Health: Why I’m Fundraising for Breast Cancer

Two impactful women in my life were diagnosed with cancer, and in their honor, two of these initiatives will support cancer research. The first of these will focus on breast cancer. The post Security & Health: Why I m Fundraising for Breast Cancer appeared first on Olivia A. Gallucci .

DEW #141 – K8s Detection Engineering, macOS EDR evasion, Cloud-native detection handbook

This issue of DEW highlights Kubernetes detection engineering, macOS EDR evasion, and building mature cloud-native detection programs. The post DEW #141 K8s Detection Engineering, macOS EDR evasion, Cloud-native detection handbook appeared first on Olivia A. Gallucci .

EDR Evasion with Lesser-Known Languages & macOS APIs

How macOS malware written in lesser-known languages evades EDRs by exploiting gaps in static analysis, API hooking, and limited telemetry. The post EDR Evasion with Lesser-Known Languages & macOS APIs appeared first on Olivia A. Gallucci .

Code Obfuscation Techniques on macOS: Beyond Packers

Explore advanced code obfuscation techniques used on macOS, beyond packers, and their role in offensive and defensive ops. The post Code Obfuscation Techniques on macOS: Beyond Packers appeared first on Olivia A. Gallucci .

Why Packers are Rare and Sus on macOS

Why third-party executable packers are rare on macOS, how they conflict with Apple's security model, and why their presence signals yikes The post Why Packers are Rare and Sus on macOS appeared first on Olivia A. Gallucci .

Signature-based Analysis for Reversing

Reversing Apple's OS components often involves a hybrid approach: using whatever OSS is available, alongside the binaries and signatures. The post Signature-based Analysis for Reversing appeared first on Olivia A. Gallucci .