The Art of Mac Malware, Volume 2
AdvancedMalwaremacOSDetection

The Art of Mac Malware, Volume 2

Detecting Malicious Software

4 / 5

The detection-focused sequel to Volume 1, Wardle turns from analyzing Mac malware to building the heuristics and tooling that catch it, using macOS's security frameworks and real-world malware samples throughout.

Buy on Amazon

As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.

Published
2025
Publisher
No Starch Press
Pages
376
Language
English

Read this if

Detection engineers and blue teamers who already have Volume 1's analysis grounding and now need to build detections, not just read samples. Shows how to program against macOS's own security-centric frameworks (Endpoint Security, ESF) rather than relying only on third-party AV.

Skip this if

Readers who haven't worked through Volume 1's foundations first (Mach-O, code signing, persistence taxonomy); this book assumes that vocabulary and builds detection logic on top of it rather than re-teaching it.

Key takeaways

  • Detection, not just analysis, is the book's whole focus — moving from "what is this sample doing" to "how do I catch the next one like it."
  • Builds heuristics directly on top of macOS's own security frameworks (Endpoint Security) instead of treating the OS as a black box.
  • Every technique is grounded in real malware families Wardle has tracked through Objective-See, not synthetic examples.

Notes

The direct sequel to The Art of Mac Malware, Volume 1 (already in this catalog) — read that one first for the Mach-O and persistence fundamentals, then this one for the detection engineering built on top of them. Pairs with Wardle's free Objective-See tools (BlockBlock, KnockKnock, Lulu), which exist as a practical demonstration of the same detection philosophy.

Related topics