<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Macos on Martin&#39;s Blog</title>
		<link>https://mac.sploit.dk/tags/macos/</link>
		<description>Recent content in Macos on Martin&#39;s Blog</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://mac.sploit.dk/tags/macos/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>When Your Expensive EDR Is Blind: Creating Your Own Detections</title>
				<link>https://mac.sploit.dk/blog/detecting-the-kelpdao-bridge-intrusion/</link>
				<pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
				<guid>https://mac.sploit.dk/blog/detecting-the-kelpdao-bridge-intrusion/</guid>
				<description>A friend&amp;rsquo;s EDR and managed service stayed silent through a $292M bridge theft. So I took the public incident report, pulled the three recovered macOS samples, and analysed them statically: a Go-based trojanized Terraform provider, a Rust Telegram stealer, and a Rust Nostr RAT, to see whether I could turn the tradecraft into durable behavioral detections. Decompiling the loader, carving the embedded Python stealer, tracing the async Nostr dispatcher by xref, and mapping every confirmed TTP to a CrowdStrike Custom IOA. All without running the malware.</description>
			</item>
	</channel>
</rss>
