// Comparison
The Art of Mac Malware, Volume 2 vs Evading EDR: Which Should You Read?
Two cybersecurity books on Malware, compared honestly: who each is for, what each does best, and which to read first.
The detection-focused sequel to Volume 1, Wardle turns from analyzing Mac malware to building the heuristics and tooling that catch it, using macOS's security frameworks and real-world malware samples throughout.
A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.
Read this if
Skip this if
Key takeaways
- Detection, not just analysis, is the book's whole focus — moving from "what is this sample doing" to "how do I catch the next one like it."
- Builds heuristics directly on top of macOS's own security frameworks (Endpoint Security) instead of treating the OS as a black box.
- Every technique is grounded in real malware families Wardle has tracked through Objective-See, not synthetic examples.
- EDR is a collection of telemetry sources, not a monolith; evasion means knowing which source sees what.
- Most durable bypasses attack the sensor's data collection, not its detection logic.
- Vendor-agnostic understanding outlives any specific bypass, which vendors patch fast.
How they compare
The Art of Mac Malware, Volume 2 and Evading EDR are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.
Both books target advanced-level readers, so the choice is about topic, not difficulty.
The Art of Mac Malware, Volume 2 and Evading EDR both cover Malware, Detection, so reading them in sequence reinforces the same material from different angles.
Keep reading
The Art of Mac Malware, Volume 2
→ Alternatives to The Art of Mac Malware, Volume 2→ What to read after The Art of Mac Malware, Volume 2