Skip to content

Gatekeeper Approved Apps

Evidence: Gatekeeper Approved Apps
Description: Collect Gatekeeper apps allowed to run
Category: System
Platform: macos
Short Name: gatekapp
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Gatekeeper approved apps list shows binaries allowed to run by Gatekeeper exceptions. This data is essential for understanding application allow-listing and detecting unauthorized approvals.

This collector gathers structured data about gatekeeper approved apps.

FieldDescriptionExample
PathPathExample value
RequirementRequirementExample value
CTimeC Time123
MTimeM Time123
LastChangeTimeLast Change Time2023-10-15 14:30:25+03:00
ModificationTimeModification Time2023-10-15 14:30:25+03:00

This collector queries the gatekeeper_approved_apps table via osquery and records results into gatekeeper_apps.

This evidence is crucial for forensic investigations as it highlights exceptions and approvals that may indicate policy bypass or persistence via whitelisted binaries.