Run the Kandji EDR
attack simulation
Use Kandji's attack simulation script for EDR, developed by Kandji’s Security Research team. This tool lets you visualize security detections in a real life scenario involving a multi-stage attack. See how to download the script, make it executable, and run it with admin privileges.
Access the Simulation on GitHub
Before testing, set the response settings in the Avert Library Item to "Protect" and add the Avert Library Item to the Blueprint your test device is assigned to. See the Kandji Knowledge Base article on Configuring the Avert Library Item.
Kandji Security Research
Learn about the latest attacks and exploits targeting Mac users
- Threat IntelligenceApril 14, 2025
PasivRobber: Chinese Spyware or Security Tool?
On March 13, 2025, our team found a suspicious mach-O file on Virustotal named wsus. After our initial analysis of this file and the package which ins
Keep reading - Threat IntelligenceApril 4, 2025
Caught in the WebKit: Getting Tangled with CVE-2025-24201
Web browsers are the gateway to the internet, a ubiquitous fixture of every enterprise device—making them a critical point of exposure. When managing
Keep reading - Threat IntelligenceFebruary 21, 2025
Uncovering Apple Vulnerabilities: diskarbitrationd and storagekitd Audit Part 3
Over the past two parts of this series, we’ve explored vulnerabilities in macOS’s diskarbitrationd daemon. In part 1, we explored how an attacker coul
Keep reading
Manage and secure your Apple devices at scale.
