This custom analytic may be used to report on activity of the xattr binary used to clear all extended attributes or the com.apple.quarantine extended attribute from files. This detection functions by monitoring for usage of the xattr binary with the -c and -d options (with com.apple.quarantine) used to clear all or a target extended attribute from a file.
The com.apple.quarantine extended attribute serves as a critical element to ensure important checks for malicious code are performed. When a file is downloaded via a browser or macOS client, the com.apple.quarantine bit is attached to the file, which triggers both a user confirmation prompt and Gatekeeper scan upon first launch.
Requirements
One or more existing plans in the Jamf Protect web app.
- In Jamf Protect, click .
- Click Create Custom Analytic at the top of the screen.
- Complete the following fields:
- Leave the remaining fields at their default selections.
- Click Save and verify that the custom analytic appears under .
- Click .
- Enter a name and select ExtendedAttributesActivity, then click Save.
- In Jamf Protect, click Plans.
- Select a plan, then click Edit.
- Select the analytic set that contains the ExtendedAttributesActivity analytic, then click Save to deploy.