Endpoint threat prevention monitors process execution to prevent known malware and threats on macOS. Endpoint threat prevention uses the Jamf Protect threat database to monitor computers for processes that match entries. When matches occur, Jamf Protect automatically blocks the matching process and quarantines the associated file.
One technique that malicious actors use to infiltrate and steal data, is to hide their malware in plain sight. For example, the Atomic Stealer malware disguised itself as a legitimate piece of free software. The download link to the software was only accessed by a sponsored search result link. Users assumed they were clicking a sponsored advertisement to a legitimate website, and downloading the legitimate application. However, this application tricked users into providing their system password and then used it to gain access to passwords and other sensitive information. The Jamf Threat Labs team was able to immediately recognize the vulnerability and update the threat database to secure Jamf Protect users from installing the false application. This scenario demonstrates the importance of a full Trusted Access implementation to proactively protect computers from malicious software. See the Atomic Stealer spread through sponsored Ads.