Complete Rapid Incident Response on macOS with Aftermath

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

A full Trusted Access implementation secures and mitigates threats, but even computers that are compliant and pose a low-security risk can become comprised.

To help you investigate, you can use Aftermath, an open-source utility from Jamf Threat Labs. Aftermath specializes in rapid incident response for macOS, which allows you to collect the data necessary to analyze a compromised Mac computer.

To help you investigate, you can use Aftermath, an open-source utility from Jamf Threat Labs. Aftermath specializes in rapid incident response for macOS, which allows you to collect the data necessary to analyze a compromised Mac computer.

Jamf recommends you upload the Aftermath.pkg to Jamf Pro and install the app using a policy. You can then create another Jamf Pro policy to run Aftermath with a specific trigger.

Example:

In Jamf Pro, you create a smart computer group that includes computers with a Jamf Protect analytic detection. Then, create a policy than runs Aftermath on all computers in the scope of the smart group. This automates both threat detection and response.