Unsupported macOS version


Description

Check that all laptops on the corporate environment are on a version of MacOS supported by IT.

Query · python

SUPPORTED_VERSIONS = [
    "10.15.1",
    "10.15.2",
    "10.15.3",
]


def rule(event):
    return (
        event.get("name") == "pack_vuln-management_os_version"
        and event.deep_get("columns", "platform") == "darwin"
        and event.deep_get("columns", "version") not in SUPPORTED_VERSIONS
        and event.get("action") == "added"
    )

Analyst notes

Update the MacOs version

Raw source Unsupported macOS version · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: osquery_outdated_macos.py
RuleID: "Osquery.UnsupportedMacOS"
DisplayName: "Unsupported macOS version"
Enabled: true
LogTypes:
  - Osquery.Differential
Tags:
  - Osquery
  - Compliance
Severity: Low
Description: >
  Check that all laptops on the corporate environment are on a version of MacOS supported by IT.
Runbook: Update the MacOs version
Reference: https://support.apple.com/en-eg/HT201260
SummaryAttributes:
  - name
  - hostIdentifier
  - action
Tests:
  - Name: MacOS out of date
    ExpectedResult: true
    Log:
      {
        "action": "added",
        "calendarTime": "Tue Sep 11 16:14:21 2018 UTC",
        "columns":
          {
            "build_distro": "10.14.2",
            "build_platform": "darwin",
            "config_hash": "1111",
            "config_valid": "1",
            "counter": "14",
            "global_state": "0",
            "extensions": "active",
            "instance_id": "1111",
            "pid": "223",
            "platform": "darwin",
            "resident_size": "54894592",
            "start_time": "1536634519",
            "system_time": "12472",
            "user_time": "31800",
            "uuid": "37821E12-CC8A-5AA3-A90C-FAB28A5BF8F9",
            "version": "Not Supported",
            "watcher": "92",
          },
        "counter": "255",
        "decorations": { "host_uuid": "1111", "environment": "corp" },
        "epoch": "0",
        "hostIdentifier": "test.lan",
        "log_type": "result",
        "name": "pack_vuln-management_os_version",
        "unixTime": "1536682461",
      }
  - Name: MacOS up to date
    ExpectedResult: false
    Log:
      {
        "action": "added",
        "calendarTime": "Tue Sep 11 16:14:21 2018 UTC",
        "columns":
          {
            "build_distro": "10.15.1",
            "build_platform": "darwin",
            "config_hash": "1111",
            "config_valid": "1",
            "counter": "14",
            "global_state": "2",
            "extensions": "active",
            "instance_id": "1111",
            "pid": "223",
            "platform": "darwin",
            "resident_size": "54894592",
            "start_time": "1536634519",
            "system_time": "12472",
            "user_time": "31800",
            "uuid": "37821E12-CC8A-5AA3-A90C-FAB28A5BF8F9",
            "version": "10.15.2",
            "watcher": "92",
          },
        "counter": "255",
        "decorations": { "host_uuid": "1111", "environment": "corp" },
        "epoch": "0",
        "hostIdentifier": "test.lan",
        "log_type": "result",
        "name": "pack_vuln-management_os_version",
        "unixTime": "1536682461",
      }


# ------ paired body: osquery_outdated_macos.py ------

SUPPORTED_VERSIONS = [
    "10.15.1",
    "10.15.2",
    "10.15.3",
]


def rule(event):
    return (
        event.get("name") == "pack_vuln-management_os_version"
        and event.deep_get("columns", "platform") == "darwin"
        and event.deep_get("columns", "version") not in SUPPORTED_VERSIONS
        and event.get("action") == "added"
    )

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.