Skip to content

Gatekeeper

Evidence: Gatekeeper
Description: Collect Gatekeeper details
Category: System
Platform: macos
Short Name: gatek
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Gatekeeper is macOS’s security feature that controls which applications can run on the system. This data is essential for understanding application security policies, detecting bypassed controls, and investigating application-based incidents.

This collector gathers structured data about gatekeeper.

FieldDescriptionExample
AssessmentEnabledAssessment Enabled123
DevIDEnabledDev ID Enabled123
VersionVersionExample value
OpaqueVersionOpaque VersionExample value

This collector queries the gatekeeper table via osquery and collects related policy files under /var/db/SystemPolicyConfiguration/.

This evidence is crucial for forensic investigations as it reveals Gatekeeper configuration and state, helping identify weakened protections or policy tampering.