Gatekeeper Approved Apps

Overview

Evidence: Gatekeeper Approved Apps
Description: Collect Gatekeeper apps allowed to run
Category: System
Platform: macos
Short Name: gatekapp
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Background

Gatekeeper approved apps list shows binaries allowed to run by Gatekeeper exceptions. This data is essential for understanding application allow-listing and detecting unauthorized approvals.

Data Collected

This collector gathers structured data about gatekeeper approved apps.

Gatekeeper Approved Apps Data

FieldDescriptionExample
PathPathExample value
RequirementRequirementExample value
CTimeC Time123
MTimeM Time123
LastChangeTimeLast Change Time2023-10-15 14:30:25+03:00
ModificationTimeModification Time2023-10-15 14:30:25+03:00

Collection Method

This collector queries the gatekeeper_approved_apps table via osquery and records results into gatekeeper_apps.

Forensic Value

This evidence is crucial for forensic investigations as it highlights exceptions and approvals that may indicate policy bypass or persistence via whitelisted binaries.