santa icon indicating copy to clipboard operation
santa copied to clipboard

Switch to evaluating the live `SecCodeRef` when authorizing new execs

Open mlw opened this issue 7 months ago • 1 comments

The SNTPolicyProcessor via MOLCodesignChecker currently evaluates the SecStaticCodeRef of a file path when a new exec is authorized. This is a legacy limitation from when Santa deployed its own kext and used the available Kauth hook since the new process wasn't completely setup yet.

Now that Santa is using the EndpointSecurity framework, the ES exec hook should not have this same limitation and we can move to using the SecCodeRef.

mlw avatar Nov 10 '23 18:11 mlw