macOS Security Testing - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Apple builds one of the strongest out-of-the-box security platforms on the market. However, determined attackers are continuously finding new and innovative ways to attack macOS that traditional security tools do not completely defend against. At Jamf, we believe effectively securing Mac computers requires an approach that aligns with Apple, instead of being forced to adapt to existing security tools for convenience.

Jamf Protect builds off of Apple's core security approach for macOS and amplifies it with better prevention, stronger controls, broader visibility, and remediation that adapts to your environment — without compromising security or Apple's signature user experience.

​​Jamf Protect's threat detection tests focus on testing these primary capabilities:

Threat Prevention
Jamf's threat prevention capabilities block and report threats before they occur. For more information and testing instructions, see Threat Prevention with Jamf Protect.
Analytics

A Jamf Protect analytic is a rule that detects suspicious user behavior and malicious system activity on macOS computers. Jamf Protect includes over 150 Jamf-managed analytics for you to deploy in your environment. Additionally, you can create custom analytics to detect activity specific to your security needs.

Analytics provide alerts whether the device is offline, remote, or online. This allows IT or InfoSec to remediate the potential threat and prevent user downtime. Analytics also provide detailed context around activity on devices to help simplify investigation and auditing on macOS.

Note:

Some of the included threat detection simulations require a minimum severity of information to be configured in the action configuration chosen in the plan used by the Mac. For more information, see Preparing Jamf Protect Cloud Action and Plan Settings for Testing.