In the next version of Santa, when paired with Workshop you'll be able to specify process tree relationships in a CEL rule.
This lets you mark executables as not usable by processes or require TouchID from the user e.g. here's an example of us preventing Claude Code from running curl w/o TouchID.
17.02.2026 15:20
π 0
π 0
π¬ 0
π 0
Day 24 of our FAAdvent Calendar: Code injection is a major threat to binary allowlisting, especially when Electron/Chromium offer easy scripting/debugging
northpole.security/blog/2025-ad...
Workshop and Santa's CEL rules can prevent attackers from using debugging options to inject malicious code.
24.12.2025 13:17
π 0
π 0
π¬ 0
π 1
Day 23 of our FAAdvent Calendar: Learn how to use Workshop's Risk Engine with entitlements to flag unauthorized VPN and remote access software, preventing data exfiltration and enforcing compliance.
northpole.security/blog/2025-ad...
23.12.2025 13:58
π 0
π 0
π¬ 0
π 1
Day 22 of our FAAdvent Calendar: macOS audio plugins are an old often overlooked persistence trick.
northpole.security/blog/2025-ad...
Malicious .component or .driver bundles dropped in well-known directories can execute code, sometimes as root.
Lock them down!
22.12.2025 14:22
π 1
π 0
π¬ 0
π 1
Day 21 of our FAAdvent Calendar: macOS's built-in security command can be used for nasty actions like dumping Keychain contents or adding rogue certificates.
Stop these attacks using Workshop and Santa CEL rules:
northpole.security/blog/2025-ad...
21.12.2025 14:02
π 0
π 0
π¬ 0
π 0
Day 20 of our FAAdvent Calendar: Living off the land (LoTL) is a common attack technique.
Learn how to use CEL rules to block potentially malicious subactions of legitimate tools like systemsetup, instead of blocking the tool entirely.
northpole.security/blog/2025-ad...
20.12.2025 14:23
π 0
π 0
π¬ 0
π 0
Day 19 of our FAAdvent Calendar: SSH private keys are master keys for your systems. π
northpole.security/blog/2025-ad...
Infostealers like Atomic, Banshee, and Cthulhu target your ~/.ssh/ folder! Learn how to lock them down with Workshop and Santaβs file access Rules.
20.12.2025 14:20
π 0
π 0
π¬ 0
π 0
π’ Weβve just released version 2025.1010 of Workshop
This release adds:
π on-demand monitor mode
π optional automatic updates
π event export to S3/GCS
π near-realtime directory syncing
π local user/group management
π added cwd & euid fields to CEL rules
π live online status on the host details page
20.12.2025 14:18
π 0
π 0
π¬ 0
π 0
Day 18 of our FAAdvent Calendar: Don't let "Sploitlight" (CVE-2025-31199) leak your sensitive macOS data!
northpole.security/blog/2025-ad...
Attacks bypass TCC to exfiltrate files like Apple Intelligence databases.
See how to prevent this persistence trick and data theft with Workshop and Santa:
20.12.2025 14:17
π 0
π 0
π¬ 0
π 0
Day 17 of our FAAdvent Calendar: Enhance your password manager security! π‘οΈπ
northpole.security/blog/2025-ad...
Beyond the account password, using file access rules can prevent other apps from reading your database, protecting you even if encryption is compromised.
20.12.2025 14:16
π 0
π 0
π¬ 0
π 0
Day 16 of our FAAdvent: Attackers are using Docker on macOS to hide from security tools!
They run containers in a Linux VM, bypassing Endpoint Security Framework & can still steal credentials by mounting host volumes. See how Santa and Workshop can prevent this:
northpole.security/blog/2025-ad...
20.12.2025 14:15
π 0
π 0
π¬ 0
π 0
Day 15 of our FAAdvent Calendar: Apple changed macOS's dynamic loader to write temp files to disk, but stealthy attackers adapt.
Learn how to use Workshop & Santaβs file access rules to block this basic technique:
northpole.security/blog/2025-ad...
20.12.2025 14:14
π 0
π 0
π¬ 0
π 0
Day 14 of our FAAdvent Calendar: Learn how attackers can bypass macOS Gatekeeper by stripping the quarantine attribute with xattr, and see how to block this technique using Workshop and Santa's CEL rules.
northpole.security/blog/2025-ad...
14.12.2025 14:25
π 0
π 0
π¬ 0
π 0
Day 13 of our FAAdvent Calendar: Workshop and Santa's file access rules can lock down cron and at job persistence before attackers even get a chance to set their alarms.
northpole.security/blog/2025-ad...
14.12.2025 14:24
π 0
π 0
π¬ 0
π 0
Day 12 of our FAAdvent Calendar: Launch Agents and Daemons are a convenient way for programs to run in the background, but theyβre also a great way for malware to gain persistence on a device.
northpole.security/blog/2025-ad...
12.12.2025 12:15
π 0
π 0
π¬ 0
π 1
Day 11 of our FAAdvent Calendar: Prevent persistence by securing /etc/pam.d with a Santa file access rule. Block write attempts even from root!
northpole.security/blog/2025-ad...
11.12.2025 12:59
π 0
π 0
π¬ 0
π 1
Day 10 of our FAAdvent Calendar: A one-liner command is all you need to see if a password is legit, but Santa's CEL rules can stop this common post exploitation behavior.
northpole.security/blog/2025-ad...
10.12.2025 13:44
π 0
π 0
π¬ 0
π 1
Number eight behind a title card saying Hide Your Hashes.
Day 8 of our FAAdvent Calendar: Hide your macOS password hashes!
A one-liner command can expose the hash and salt, but Workshop & Santa's file access rules & CEL rules can protect these crown jewel files.
northpole.security/blog/2025-ad...
08.12.2025 15:16
π 0
π 0
π¬ 0
π 1
Day 7 of our FAAdvent Calendar : Prevent macOS Gatekeeper from being disabled on your fleet by creating a Santa CEL rule!
northpole.security/blog/2025-ad...
07.12.2025 14:20
π 1
π 0
π¬ 0
π 1
Day 6 of our FAAdvent Calendar: Protect your browser cookies from infostealers with Santa's File Access Rulesβlimit access so only the browser can read its own cookies!
northpole.security/blog/2025-ad...
06.12.2025 14:04
π 0
π 0
π¬ 0
π 1
Join us in celebrating North Pole Security's first anniversary! π
Reflect on a year of innovation, growth, & unwavering commitment to livable security with Santa and Workshop. Read about our journey and what's next! #FirstAnniversary #Santa #Workshop
northpole.security/blog/one-yea...
09.10.2025 17:45
π 0
π 1
π¬ 0
π 0
- Added a βCopy Detailsβ button to to FAA block dialogs
There are also a few small changes and bug fixes
Please checkout the release notes for more goodies.
29.08.2025 15:22
π 0
π 0
π¬ 0
π 0
Release v2025.8 Β· northpolesec/santa
Notes
Announcements
π Santa has a new Workshop! North Pole Security is excited to announce the release of Workshop, an official sync service specifically designed to deeply integrate with Santa. It...
Yesterday we released Santa v2025.8 on GitHub.
github.com/northpolesec...
This release includes a handful of new features. Some highlights include:
- Support for CEL string extensions to enable writing more powerful policies.
This lets you do things like args.join(" ").contains("-flag option")
29.08.2025 15:22
π 0
π 0
π¬ 1
π 0
Incredibly humbled by the amazing feedback from our community!
Thank you for growing with us - here's to continuing to build something great together! π
14.08.2025 13:21
π 0
π 0
π¬ 0
π 0
π It's Christmas in July!
We raised $4M to make proactive macOS security scalable for everyone.
Workshop is the first commercial platform built for Santa. Finally making allowlisting usable at scale.
Thanks to A16Z & everyone's who's believed in our mission.
30.07.2025 13:39
π 5
π 1
π¬ 1
π 1