Lesson 9: macOS Threat Mitigation and Alerts - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Explore threat prevention and alerts in the macOS Security portal. Safely generate an alert on a test computer and learn how Jamf Protect automatically mitigates threats on enrolled Mac computers.

Video

Key points

  • Jamf Protect contains automated threat mitigation tools that can record and resolve alerts for minor issues on enrolled computers.

  • Alerts are records of events on enrolled computers that may pose a security risk.

  • Alerts are categorized by severity:

    • Informational (0)

    • Low (1)

    • Medium (2)

    • High (3)

  • Alerts have a built-in status tracker, allowing administrators to filter new alerts and track active issues in Jamf Protect. Available statuses include:

    • New

    • In Progress

    • Resolved

    • Auto Resolved (only alerts that are automatically mitigated by threat prevention)

  • The detail view for alerts provides in-depth information about the triggering event, including:

    • A summary of the issue

    • The exact process, files, or binaries that triggered the alert

    • Any affected users and groups on the Mac

  • Analytic exceptions can be created to tell Jamf Protect to ignore specific files or binaries that would otherwise trigger an alert.

  • Jamf Protect can automatically resolve certain alerts by preventing a file or process from executing and then placing that item into quarantine.

  • Custom prevent lists can be used to block specific files or software from running on enrolled Macs.

  • Custom prevent lists can identify what file or process to block based on:

    • File hash (SHA1 or SHA256)

    • Team ID

    • Code directory hash (CDHash)

    • Signing ID

Review

To view answers, click arrow next to each question.

  1. Alerts are categorized as Informational, Low, Medium, or High in the macOS Security portal.
  2. Alerts with a status of Auto Resolved have been automatically detected and responded to by the Jamf Protect agent on an enrolled computer. The threat event has been prevented and no further action is needed to secure the computer.
  3. Custom prevent lists use either the file hash or signing information (team ID, CDHash, or signing ID) to identify and block specific files or processes on enrolled computers.

Practice

  1. On a test computer enrolled in the macOS Security portal, download the EICAR Anti-Malware Test File.

  2. Attempt to launch the EICAR test file:

    1. Open Terminal.

    2. Type sh followed by a space.

    3. Drag and drop the EICAR test file from your /Downloads directory into the Terminal window.

    4. Press Return.

  3. Confirm that the EICAR test file is no longer in your /Downloads directory.

  4. In the macOS Security portal, navigate to Alerts in the sidebar.

  5. Locate and select the Threat Prevention alert generated by the EICAR test file.

  6. Explore each of the different tabs of the Threat Prevention alert page.

Resources

Jamf Protect Documentation

EICAR