Testing and Analyzing GatekeeperBlockedRevoked - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Follow the steps below to test the GatekeeperBlockedRevoked analytic.

Warning:

Only test this detection using a virtual machine snapshot.

Requirements

Download Proton from the Objective-See's macOS Malware Collection on github (https://github.com/objective-see/Malware/raw/main/Proton.zip).

  1. Open the downloaded file. When prompted, enter the following password: infect3d.
  2. Open the following folder: Proton/Proton.C.
  3. Double-Click Elmedia Player.dmg.
  4. Drag the Elmedia Player.app to your Desktop.
  5. Open the Elmedia Player.app on your Desktop.
  6. On the virtual machine, confirm that a macOS pop-up window appears that prompts you.
    After completing the testing simulation, a new alert titled GatekeeperBlockedRevokedappears in the Jamf Protect Cloud.
    Note:

    On macOS 10.14 and prior, an XProtectDetection entry appears. On macOS 10.15 and later, a GatekeeperBlockedRevoked entry appears. This alert is triggered because the application is signed with a developer ID that was explicitly revoked by Apple.

  7. Open and review the GatekeeperBlockedRevoked alert. The most interesting data points when analyzing this alert are:
    • Summary > Gatekeeper Event Details > Message: Provides information about what application was blocked by Gatekeeper.

    • Processes > Signing Info: Provides information about the application's signing information.

    In a real world scenario, investigation of this alert should begin with reviewing the application that was blocked. Determine if you recognize it and view the signingInfo fields of the process to determine if it's properly signed by the developer. Gatekeeper does not always provide exact details as to why it has chosen to block an application.

  8. If a virtual machine snapshot was taken prior to completing this test scenario the easiest cleanup method is to revert to the snapshot. Otherwise, remove the downloaded file and the extracted contents from the virtual Mac.