Run the Kandji EDR
Attack Simulator
Use Kandji's attack simulation script for EDR, developed by Kandji’s Security Research team. This tool lets you visualize security detections in a real life scenario involving a multi-stage attack. See how to download the script, make it executable, and run it with admin privileges.
Access the Simulator on GitHub
Before testing, set the response settings in the Avert Library Item to "Protect" and add the Avert Library Item to the Blueprint your test device is assigned to. See the Kandji Knowledge Base article on Configuring the Avert Library Item.
Kandji Security Research
Learn about the latest attacks and exploits targeting Mac users
- Threat IntelligenceMay 9, 2025
Kandji Quarterly Threat Intelligence Report: May 2025
Welcome to the Kandji Threat Intelligence Report, our quarterly summary of emerging threats in the macOS ecosystem and how Kandji is responding in rea
Keep reading - Threat IntelligenceMay 1, 2025
macOS Vulnerabilities: A Year of Security Research at Kandji
Kandji security researchers have been hard at work hunting for vulnerabilities in macOS, reporting them to Apple before malicious actors can exploit t
Keep reading - Threat IntelligenceApril 14, 2025
PasivRobber: Chinese Spyware or Security Tool?
On March 13, 2025, our team found a suspicious mach-O file on Virustotal named wsus. After our initial analysis of this file and the package which ins
Keep reading
Manage and secure your Apple devices at scale.
