North Pole Security's Avatar

North Pole Security

@northpolesec

North Pole Security account. We make Santa https://github.com/northpolesec/santa

27
Followers
3
Following
81
Posts
19.10.2024
Joined
Posts Following

Latest posts by North Pole Security @northpolesec

Video thumbnail

In the next version of Santa, when paired with Workshop you'll be able to specify process tree relationships in a CEL rule.

This lets you mark executables as not usable by processes or require TouchID from the user e.g. here's an example of us preventing Claude Code from running curl w/o TouchID.

17.02.2026 15:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 24 of our FAAdvent Calendar: Code injection is a major threat to binary allowlisting, especially when Electron/Chromium offer easy scripting/debugging

northpole.security/blog/2025-ad...

Workshop and Santa's CEL rules can prevent attackers from using debugging options to inject malicious code.

24.12.2025 13:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 23 of our FAAdvent Calendar: Learn how to use Workshop's Risk Engine with entitlements to flag unauthorized VPN and remote access software, preventing data exfiltration and enforcing compliance.

northpole.security/blog/2025-ad...

23.12.2025 13:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 22 of our FAAdvent Calendar: macOS audio plugins are an old often overlooked persistence trick.

northpole.security/blog/2025-ad...

Malicious .component or .driver bundles dropped in well-known directories can execute code, sometimes as root.

Lock them down!

22.12.2025 14:22 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 21 of our FAAdvent Calendar: macOS's built-in security command can be used for nasty actions like dumping Keychain contents or adding rogue certificates.

Stop these attacks using Workshop and Santa CEL rules:

northpole.security/blog/2025-ad...

21.12.2025 14:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 20 of our FAAdvent Calendar: Living off the land (LoTL) is a common attack technique.

Learn how to use CEL rules to block potentially malicious subactions of legitimate tools like systemsetup, instead of blocking the tool entirely.

northpole.security/blog/2025-ad...

20.12.2025 14:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 19 of our FAAdvent Calendar: SSH private keys are master keys for your systems. πŸ”‘

northpole.security/blog/2025-ad...

Infostealers like Atomic, Banshee, and Cthulhu target your ~/.ssh/ folder! Learn how to lock them down with Workshop and Santa’s file access Rules.

20.12.2025 14:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

πŸ“’ We’ve just released version 2025.1010 of Workshop

This release adds:
πŸŽ„ on-demand monitor mode
πŸŽ„ optional automatic updates
πŸŽ„ event export to S3/GCS
πŸŽ„ near-realtime directory syncing
πŸŽ„ local user/group management
πŸŽ„ added cwd & euid fields to CEL rules
πŸŽ„ live online status on the host details page

20.12.2025 14:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 18 of our FAAdvent Calendar: Don't let "Sploitlight" (CVE-2025-31199) leak your sensitive macOS data!

northpole.security/blog/2025-ad...

Attacks bypass TCC to exfiltrate files like Apple Intelligence databases.

See how to prevent this persistence trick and data theft with Workshop and Santa:

20.12.2025 14:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 17 of our FAAdvent Calendar: Enhance your password manager security! πŸ›‘οΈπŸ”

northpole.security/blog/2025-ad...

Beyond the account password, using file access rules can prevent other apps from reading your database, protecting you even if encryption is compromised.

20.12.2025 14:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 16 of our FAAdvent: Attackers are using Docker on macOS to hide from security tools!

They run containers in a Linux VM, bypassing Endpoint Security Framework & can still steal credentials by mounting host volumes. See how Santa and Workshop can prevent this:

northpole.security/blog/2025-ad...

20.12.2025 14:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 15 of our FAAdvent Calendar: Apple changed macOS's dynamic loader to write temp files to disk, but stealthy attackers adapt.

Learn how to use Workshop & Santa’s file access rules to block this basic technique:

northpole.security/blog/2025-ad...

20.12.2025 14:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 14 of our FAAdvent Calendar: Learn how attackers can bypass macOS Gatekeeper by stripping the quarantine attribute with xattr, and see how to block this technique using Workshop and Santa's CEL rules.

northpole.security/blog/2025-ad...

14.12.2025 14:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 13 of our FAAdvent Calendar: Workshop and Santa's file access rules can lock down cron and at job persistence before attackers even get a chance to set their alarms.

northpole.security/blog/2025-ad...

14.12.2025 14:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Day 12 of our FAAdvent Calendar: Launch Agents and Daemons are a convenient way for programs to run in the background, but they’re also a great way for malware to gain persistence on a device.

northpole.security/blog/2025-ad...

12.12.2025 12:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 11 of our FAAdvent Calendar: Prevent persistence by securing /etc/pam.d with a Santa file access rule. Block write attempts even from root!

northpole.security/blog/2025-ad...

11.12.2025 12:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 10 of our FAAdvent Calendar: A one-liner command is all you need to see if a password is legit, but Santa's CEL rules can stop this common post exploitation behavior.

northpole.security/blog/2025-ad...

10.12.2025 13:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Number eight behind a title card saying Hide Your Hashes.

Number eight behind a title card saying Hide Your Hashes.

Day 8 of our FAAdvent Calendar: Hide your macOS password hashes!

A one-liner command can expose the hash and salt, but Workshop & Santa's file access rules & CEL rules can protect these crown jewel files.

northpole.security/blog/2025-ad...

08.12.2025 15:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 7 of our FAAdvent Calendar : Prevent macOS Gatekeeper from being disabled on your fleet by creating a Santa CEL rule!

northpole.security/blog/2025-ad...

07.12.2025 14:20 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Post image

Day 6 of our FAAdvent Calendar: Protect your browser cookies from infostealers with Santa's File Access Rulesβ€”limit access so only the browser can read its own cookies!

northpole.security/blog/2025-ad...

06.12.2025 14:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
North Pole Security Advent Calendar: 25 Days of macOS Protection Discover 25 production-ready Santa rules inspired by actual macOS malware. Each day reveals a new CEL or FAA configuration to protect against threats like Atomic Stealer and threat campaigns targeting...

We've started our FAAdvent Calendar a collection of short things you can do with Workshop and Santa to improve improve your security while staying productive.

northpole.security/blog/2025-ad...

05.12.2025 14:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Introducing On-Demand Monitor Mode in Santa and Workshop πŸš€πŸŽ… In this video, I introduced a new feature called on-demand monitor mode that will be available in the next versions of Santa and Workshop. This feature allows users to temporarily switch from lockdown...

'Tis the season for new features. 🎁

Introducing On-Demand Monitor Mode in Workshop & Santaβ€”monitor mode access only when you need it, only when you prove you're at the keyboard.

Check out the Loom ⬇️

www.loom.com/share/0c09ed...

01.12.2025 12:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Join us in celebrating North Pole Security's first anniversary! πŸŽ‰

Reflect on a year of innovation, growth, & unwavering commitment to livable security with Santa and Workshop. Read about our journey and what's next! #FirstAnniversary #Santa #Workshop

northpole.security/blog/one-yea...

09.10.2025 17:45 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

- Added a β€œCopy Details” button to to FAA block dialogs

There are also a few small changes and bug fixes

Please checkout the release notes for more goodies.

29.08.2025 15:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Release v2025.8 Β· northpolesec/santa Notes Announcements πŸŽ‰ Santa has a new Workshop! North Pole Security is excited to announce the release of Workshop, an official sync service specifically designed to deeply integrate with Santa. It...

Yesterday we released Santa v2025.8 on GitHub.
github.com/northpolesec...

This release includes a handful of new features. Some highlights include:

- Support for CEL string extensions to enable writing more powerful policies.

This lets you do things like args.join(" ").contains("-flag option")

29.08.2025 15:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Incredibly humbled by the amazing feedback from our community!

Thank you for growing with us - here's to continuing to build something great together! πŸš€

14.08.2025 13:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Release v2025.7 Β· northpolesec/santa Notes Announcements πŸŽ‰ Santa has a new Workshop! North Pole Security is excited to announce the release of Workshop, an official sync service specifically designed to deeply integrate with Santa. It...

Keeping with our Christmas in JulyπŸŽ„, we just released Santa 2025.7 on GitHub github.com/northpolesec...

This release includes:

- A new icon that matches the company's branding
- Ready for Tahoe!
- Bug fixes and more

31.07.2025 16:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
North Pole Security Raises $4M to Bring Scalable, Proactive Endpoint Protection to the Enterprise NEW YORK, July 30, 2025 (GLOBE NEWSWIRE) -- North Pole Security today announced it has raised $4 million in seed funding to deliver the first scalable, enterprise-grade endpoint protection platform fo...

Press release can be found at apnews.com/press-releas...

30.07.2025 14:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

πŸŽ‰ It's Christmas in July!

We raised $4M to make proactive macOS security scalable for everyone.

Workshop is the first commercial platform built for Santa. Finally making allowlisting usable at scale.

Thanks to A16Z & everyone's who's believed in our mission.

30.07.2025 13:39 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 1
Preview
Release v2025.6 Β· northpolesec/santa Notes ImportantThe binaries initially uploaded for this release only contained the arm64 slice. We have updated the binaries to be universal and also include the x86_64 slice as well. You may need ...

There are also many other updates and bug fixes

Be sure to check out the release notes for full details!

github.com/northpolesec...

08.07.2025 13:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0