Automating Rapid Security Responses on macOS with Aftermath and Jamf Pro

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Running Aftermath immediately after a threat is detected ensures the collected data fully represents the state of the comprised devices. As a result, Jamf recommends using a Jamf Pro policy and smart groups to automatically run Aftermath when a threat is detected.

Requirements
  1. Upload Aftermath.pkg to Jamf Pro.
  2. Create a Jamf Pro policy that installs Aftermath.pkg on all managed computers.
  3. Create a policy that runs Aftermath when triggered.

    For information about available commands, see jamf / aftermath in Jamf's open source Github repository.

Aftermath is ready to perform a rapid security response based on the policy trigger you created in Jamf Pro. When run, Aftermath writes the collected data in a ZIP file to the /tmp directory; however, you can customize the output location with the --output argument.