
The Art of Mac Malware, Volume 2
Detecting Malicious Software
The detection-focused sequel to Volume 1, Wardle turns from analyzing Mac malware to building the heuristics and tooling that catch it, using macOS's security frameworks and real-world malware samples throughout.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Patrick Wardle
- Published
- 2025
- Publisher
- No Starch Press
- Pages
- 376
- Language
- English
Read this if
Detection engineers and blue teamers who already have Volume 1's analysis grounding and now need to build detections, not just read samples. Shows how to program against macOS's own security-centric frameworks (Endpoint Security, ESF) rather than relying only on third-party AV.
Skip this if
Readers who haven't worked through Volume 1's foundations first (Mach-O, code signing, persistence taxonomy); this book assumes that vocabulary and builds detection logic on top of it rather than re-teaching it.
Key takeaways
- Detection, not just analysis, is the book's whole focus — moving from "what is this sample doing" to "how do I catch the next one like it."
- Builds heuristics directly on top of macOS's own security frameworks (Endpoint Security) instead of treating the OS as a black box.
- Every technique is grounded in real malware families Wardle has tracked through Objective-See, not synthetic examples.
Notes
The direct sequel to The Art of Mac Malware, Volume 1 (already in this catalog) — read that one first for the Mach-O and persistence fundamentals, then this one for the detection engineering built on top of them. Pairs with Wardle's free Objective-See tools (BlockBlock, KnockKnock, Lulu), which exist as a practical demonstration of the same detection philosophy.
What to read before
What to read before The Art of Mac Malware, Volume 2 →Intermediate · 2018
Malware Data Science
Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.
Advanced · 2024
Evading EDR
A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.
Advanced · 2022
The Art of Mac Malware, Volume 1
Patrick Wardle's deep dive on macOS malware analysis: persistence patterns, injection techniques, anti-analysis tricks, and the macOS-specific tooling needed to triage real samples.
What to read next
What to read after The Art of Mac Malware, Volume 2 →Advanced · 2024
Evading EDR
A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.
Advanced · 2022
The Art of Mac Malware, Volume 1
Patrick Wardle's deep dive on macOS malware analysis: persistence patterns, injection techniques, anti-analysis tricks, and the macOS-specific tooling needed to triage real samples.
Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.
Explore similar books
Alternatives to The Art of Mac Malware, Volume 2 →Advanced · 2024
Evading EDR
A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.
Advanced · 2022
The Art of Mac Malware, Volume 1
Patrick Wardle's deep dive on macOS malware analysis: persistence patterns, injection techniques, anti-analysis tricks, and the macOS-specific tooling needed to triage real samples.
Intermediate · 2018
Malware Data Science
Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.