macOS

Version: macOS (Sierra, High Sierra, Mojave, Catalina, Big Sur, Monterey, and Ventura)

Netsurion Open XDR provides support for devices running Apple’s macOS. Netsurion Open XDR can extract logs from OS devices and can generate flex reports and triggering alerts due to suspicious activity associated with login/logout activity, authentication failures and any kind of administrator activity.

Netsurion data source integration for macOS allows you to monitor the following components:

  • Security – User authentication failure.
  • Compliance – User and group management, administrative activities and command executed.
  • Operation – Login and logout activities, login failure activities, authentication, and authorization.

Once macOS is configured to deliver logs to Netsurion Open XDR; alerts, dashboards and reports can be configured into Netsurion Open XDR.

The following are the key Data Source Integration available in Netsurion Open XDR.

Alerts

Type Name Description
Security macOS – User authentication failure This alert will be generated when the user authentication fails.
Compliance macOS – Login Failure This alert will be generated when the user login failure is attempted.

Reports

Type Name Description
Operations macOS – User and Group management This report gives information about user and group management activities like modification, creation, and addition.
Operations macOS – Administrative activities This report gives the information about any kind of administrative activities in macOS.
Operations macOS – Command executed This report gives information about command executed by users.
Compliance macOS – Login and Logout activities This report gives information about user login and logout activities based on local or remote.
Compliance macOS – Authentication and Authorization This report gives the information about user authentication and authorization activities in macOS.

Documentation

The configuration details are consistent with Netsurion Open XDR 9.3 or later, and macOS.

Download Integration Guide and How-to Guide for configuration instructions and more information.