Mac Security Posture Pro
com.maccrab.forensics.posture-pro
Publisher description
Current runtime: this plugin runs unsandboxed with MacCrab's access. Any sandbox wording in the publisher's signed description below reflects an earlier design. The access disclosure on this page describes the current execution path.
Collection limitation in v0.3.1: unavailable checks can distort the overall grade, and some unreadable sources may appear empty. Inspect the individual checks and access limitations; the grade does not establish that every source was assessed.
A read-only security-posture collector AND machine inventory. It grades the Mac's hardening controls and enumerates everything on it that matters for a forensic timeline — so even a hardened Mac produces a rich, cross-referenceable corpus rather than a row of green checkmarks.
GRADE (score 0–100 + letter): • SIP, FileVault, Gatekeeper — the critical controls • Application Firewall (+ stealth mode) • XProtect malware-definition freshness • Download quarantine (LSQuarantine active?) • Launchd persistence integrity — resolves each LaunchDaemon/LaunchAgent program and code-signs it; flags unsigned / ad-hoc / unverifiable entries • Privacy-permission exposure (TCC)
INVENTORY (one artifact per item): • Every launchd persistence item — path, resolved program, signing verdict + Team ID • Non-Apple TCC privacy grants — service + bundle-id, high-risk flagged (never the grant bodies) • Login / background items (BTM) — identifier, developer, type, enabled/allowed • System extensions (NetworkExtension / Endpoint Security / DriverKit) + third-party kernel extensions • Configuration profiles (MDM / manual) — identifier, org, scope • Recent download-quarantine events — agent + timestamp + type ONLY (never the download URL)
COLLECTION (v0.3.0): code-signing (SecStaticCode), TCC + quarantine (SQLite), and SIP (IOKit NVRAM) run IN-PROCESS — no subprocess. FileVault / Gatekeeper / firewall / extensions / login items / profiles remain declared subprocess probes that degrade gracefully when the sandbox denies them.
Emits verdicts, counts, paths and bundle-ids only — no file contents, no secrets, no download URLs, no message/mail data.
What it reads
Publisher-declared sources for this catalog entry. This list describes intended collection; it does not confine an unsandboxed plugin's file access. The published app's install screen may show older static descriptions rather than the publisher declarations shown here.
SIP / FileVault / Gatekeeper / firewall state (system tools)XProtect bundle Info.plistLaunchDaemons / LaunchAgents plists + codesign verdictsTCC.db (non-Apple client ids + services only)System extensions (systemextensionsctl) + third-party kernel extensions (kmutil)Login / background items — Background Task Management (sfltool dumpbtm)Configuration profiles (profiles)Download-quarantine events — agent + timestamp + type only, never URLs (LSQuarantine)
Access and output privacy
Declared privacy requirements and the current execution path. Output classification describes what the plugin emits; it is separate from the files its process can read.
- Declared macOS access
- Full Disk Access
(kTCCServiceSystemPolicyAllFiles)
- Full Disk Access
- Declared output Metadata — may include sensitive paths, identities, and security settings. Encryption is not required by this classification.
- Runtime Trusted, unsandboxed process. MacCrab validates its Developer ID signature before execution. It inherits the host's privileges, including available Full Disk Access.
- Network The first-party execution path does not enforce an outbound-network block. A publisher's declaration of no network use is a behavior claim.
What it emits
Structured record types this plugin produces. Each row in your case database is one of these.
posture.reportposture.factorposture.persistence_itemposture.tcc_grantposture.quarantine_eventposture.login_itemposture.extensionposture.config_profile
Sample output
Real-shape examples of what this plugin produces. One per content type. The platform stores each emit as a row in your case database.
posture.report
The Overview grade card — a derived headline with the letter grade, score, per-category rollup and flagged count.{"kind":"artifact","artifact":{"contentType":"posture.report","summary":"Security posture: grade B (82/100) — 2 item(s) flagged","privacyClass":"metadata","confidence":"derived","data":{"schemaVersion":2,"generatedAt":"2026-07-01T00:00:00Z","score":82,"grade":"B","flaggedCount":2,"categoryCounts":{"persistence":10,"tcc":0,"quarantine":171,"login_items":0,"extensions":29,"config_profiles":0}}}}posture.factor
A scored control verdict — the persistence integrity factor.{"kind":"artifact","artifact":{"contentType":"posture.factor","summary":"Launchd persistence integrity: fail","privacyClass":"metadata","confidence":"observed","data":{"key":"persistence","title":"Launchd persistence integrity","status":"fail","weight":12,"detail":"Scanned 10 launchd item(s); 1 unsigned / ad-hoc / script / unverifiable.","remediation":"Investigate the flagged launchd entries — unsigned persistence is a common malware foothold.","evidence":["system-daemon: /Library/Application Support/Sketchy/helper [unsigned]"]}}}posture.persistence_item
One inventory record — a launchd item whose helper could not be verified. Every item is enumerated, signed or not.{"kind":"artifact","artifact":{"contentType":"posture.persistence_item","summary":"system-daemon: /Library/PrivilegedHelperTools/com.docker.socket [unknown]","privacyClass":"metadata","confidence":"observed","data":{"domain":"system-daemon","label":"com.docker.socket","program":"/Library/PrivilegedHelperTools/com.docker.socket","signing":"unknown","flagged":true}}}posture.extension
One inventory record — an active Endpoint Security system extension (attack surface a clean grade would hide).{"kind":"artifact","artifact":{"contentType":"posture.extension","summary":"system/endpoint_security: Vendor Endpoint Security Extension [active]","privacyClass":"metadata","confidence":"observed","data":{"class":"system","category":"endpoint_security","identifier":"com.vendor.agent","name":"Vendor Endpoint Security Extension","teamID":"AB12CD34EF","version":"1.4.2","enabled":true,"active":true,"appleSigned":false}}}posture.quarantine_event
One inventory record — a download-quarantine event. Agent + timestamp + type only; the download URL is deliberately never carried.{"kind":"artifact","artifact":{"contentType":"posture.quarantine_event","summary":"Google Chrome — 2026-06-28T18:50:20Z","privacyClass":"metadata","confidence":"observed","data":{"timestamp":"2026-06-28T18:50:20Z","timestampUnix":1782672620,"agent":"Google Chrome","typeNumber":0}}}Community screenshots
Submitted by operators — moderated, and never catalog-authoritative (the signed catalog + sample output are the source of truth).
Discussion
Operator reports, caveats, and notes. Backed by GitHub Discussions on
peterhanily/maccrab-rave-comments; sign in with GitHub to post.
Comments load from giscus.app — if you block third-party scripts, nothing appears here.
Discussion data is hosted by GitHub. The Giscus iframe loads from
giscus.app. Operators with strict third-party-loader
policies should skip this section.
Verification for v0.3.1
Release checks recorded on . These are the catalog's records for this version; this page does not perform a new independent build or collection test.
Source rebuild not applicable: this first-party entry does not publish a source repository for independent rebuilding. You can verify the publisher signature and pinned artifact digests against trusted keys. A recorded maintainer rebuild check does not provide independent source verification.
Recorded release checks
manifest-schema-v1reproducible-build-verifieddeveloper-id-signeded25519-signature-verifiedpublisher-key-pin-matchedpublisher-key-not-revoked
Revocation status comes from the signature-verified revocation list (serial 2), issued . The website checks it during its build; MacCrab checks its own verified list when installing. The issue date does not describe the client's last successful fetch.
No revocation for v0.3.1 is recorded in that list.
Verify the signatures, artifact digests, and revocation list yourself.
Versions
Historical vetting is retained even when a release is revoked. “Current” identifies the version selected by the catalog.
| Version | Tag | Vetted | Revocation status | Reproducibility | Canonical hash |
|---|---|---|---|---|---|
| v0.1.0 | v0.1.0 | Revoked — These builds are not Developer-ID signed under the MacCrab team. MacCrab v1.21.4 and later refuse to execute an unsigned first-party plugin, because first-party plugins run unsandboxed and the code signature is what authorises that. Affected versions install successfully and then fail at run time. Superseded by 0.3.1, which is signed and verified; update to it. | Rebuild recorded as verified | 0241baddf7b52997… | |
| v0.2.0 | v0.2.0 | Revoked — These builds are not Developer-ID signed under the MacCrab team. MacCrab v1.21.4 and later refuse to execute an unsigned first-party plugin, because first-party plugins run unsandboxed and the code signature is what authorises that. Affected versions install successfully and then fail at run time. Superseded by 0.3.1, which is signed and verified; update to it. | Rebuild recorded as verified | 6c5a40ce8f7394f1… | |
| v0.3.0 | v0.3.0 | Revoked — These builds are not Developer-ID signed under the MacCrab team. MacCrab v1.21.4 and later refuse to execute an unsigned first-party plugin, because first-party plugins run unsandboxed and the code signature is what authorises that. Affected versions install successfully and then fail at run time. Superseded by 0.3.1, which is signed and verified; update to it. | Rebuild recorded as verified | 50e65e0880c46bae… | |
| v0.3.1 current | v0.3.1 | No revocation recorded | Source rebuild not applicable | 99164530a523f6e0… |