Lesson 8: macOS Threat Detection - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Configure the compliance baseline and analytic set that make up the default plan in the macOS Security portal. Deploy the plan to computers.

Video

Key points

  • Plans determine what to log, where to send data, and how the Jamf Protect agent responds to threats when detected.

    • Plans are made up of multiple components within the macOS Security portal, including compliance baseline reporting, action configurations, and analytic sets.
  • The compliance baseline is composed of recommended security settings called rules.
    • Most rules correspond with profiles in the CIS Benchmarks®.

    • Reporting can be turned on or off for each compliance rule individually or altogether within a plan.

  • Analytics are used by the Jamf Protect agent to detect suspicious behavior and malicious activity on computers.

    • Many analytics are associated with techniques in the MITRE ATT&CK® Matrix.

    • Analytic sets are groups of one or more analytics that can be applied to a plan.

  • Action configurations determine the amount of data collected and where it is stored.

    • A plan can only contain one action configuration.

  • Plans are comprehensive security configurations that are deployed to computers as configuration profiles.

  • Any changes made to a plan must be downloaded and deployed as a new configuration profile.

    • Changes to a component included in a plan do not require a new configuration profile to be deployed.

  • Automatic updates for the Jamf Protect agent can be turned on in a plan.

  • Jamf Pro can be connected to the Jamf Protect Cloud to automatically sync plans for deployment.

    • Once connected, Jamf Pro can also perform the initial deployment of the Jamf Protect package on computers in the scope of a plan configuration profile.

  • Successful deployment can be confirmed on a managed computer using one of the following methods:

    • Check for the plan configuration profile in System Settings > General > Device Management.

    • Enter the command protectctl version in Terminal to verify the Jamf Protect agent is installed.

  • Multiple plans can be created, but each computer should only have a single plan.

    • More than one plan on a computer can cause undesired behaviors and issues with communication.

Review

To view answers, click arrow next to each question.

  1. The compliance baseline is used to turn on or off the reporting of individual rules for recommended security settings.
  2. Analytics are used to detect suspicious behavior and malicious system activity.
  3. Action configurations are used to determine how much data is collected and where it is stored.

Practice

  1. Review the System Integrity Protection (SIP) Enabled rule.

    1. Navigate to Compliance > Baseline.

    2. Click the System Integrity Protection (SIP) Enabled rule.

    3. Read its description.

  2. Review the Suspicious Office Activity analytic.

    1. Navigate to Analytics > All Analytics.

    2. Click the disclosure triangle to expand the Common Attacker Technique category.

    3. Click the Suspicious Office Activity analytic.

    4. Read its summary.

  3. Review the Default plan.

    1. Navigate to Plans.

    2. Click the Default plan to review it, but do not make any changes.

Resources

Jamf Protect Documentation