Pete Markowsky's Avatar

Pete Markowsky

@plm.bsky.social

Cofounder & CEO @northpolesec.bsky.social Prev: @google working on Security Agents including Santa. Cofounder and Chief Architect @capsule8 (tweets are my own.) Personal Blog: https://blog.markowsky.us Company Website: https://northpole.security

206 Followers  |  193 Following  |  86 Posts  |  Joined: 22.06.2023  |  1.8798

Latest posts by plm.bsky.social on Bluesky

CEL has a lot of features and is often a good way to remove unneeded functionality e.g. preventing users to run Electron apps with --inspect or Chrome with remote debugging.

You can also block env vars so if you need to stop the DYLD_ env vars you can.

More CEL functionality to come.

24.12.2025 13:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A fun little entry where we can use network extension entitlements to flag remote access tools and VPNs.

macOS entitlements are kinda slept on for detection & prevention

It's not a silver bullet, but it certainly gets you a lot of coverage without maintaining a list.

23.12.2025 14:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Other fun things we posted over the weekend @northpolesec.bsky.social

- Day 21: macOS insecurity - blocking dump-keychain

northpole.security/blog/2025-ad...

- Day 20: Where's the remote - blocking users from enabling SSH & remote apple events via systemsetup

northpole.security/blog/2025-ad...

22.12.2025 14:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is another old one & a classic from
@theevilbit.bsky.social's Beyond Good Ol' LaunchAgents theevilbit.github.io/beyond/beyon...

Workshop and Santa's File access rules were built to allow you to lock down directories like this to just the apps that need it & quickly get legitimate approvals.

22.12.2025 14:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is probably the most common, known & least stealthy option for malware to persist

This year Kristin Smith gave a solid talk at BSides Canberra on using models & our file access rules to find anomalous creation LaunchDaemons

You can see the talk here youtube.com/watch?v=YJWf...

12.12.2025 12:18 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is an oldie but can still be relevant.

@theevilbit.bsky.social calls it out directly in his blog series Beyond Good Ol' LaunchAgents theevilbit.github.io/beyond/beyon...

11.12.2025 14:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is a super common technique for infostealers e.g. Huntress blogged about this yesterday

www.huntress.com/blog/amos-st...

just blogged about AMOS doing this yesterday, after tricking users to install their malware via AI generated instructions to use bash and curl.

10.12.2025 13:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Always enjoy your set lists. Thanks

10.12.2025 13:43 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

One thing I like about our system is that it's easy to make these kinda trip wires where you can lock these things down. But quickly make an exception if you need to allow something and then dial it back off.

08.12.2025 15:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
08.12.2025 12:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is another simple but powerful control. You almost never need to disable Gatekeeper. And if you do you should be able to handle that on a case by case basis.

07.12.2025 14:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Stopping things like infostealers by locking down the cookie jar to just the signed browser processes is a simple but powerful control

While Chrome is working on Device Bound Session Credentials (DBSC). You can deploy this today.

Also if you use another browser like Firefox, it'll still work.

06.12.2025 14:05 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

This is a great feature that I'm using daily.

Honestly feels like we found a solid way to close the monitor mode is always on for devs gap.

Super proud of the team @northpolesec.bsky.social for landing this

01.12.2025 12:47 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

What about the imaginary CISO?

24.10.2025 01:00 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Will be curious to get your thoughts on it. The soundtrack is great.

But something feels off about it for me.

11.10.2025 19:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Join us in celebrating North Pole Security's first anniversary! πŸŽ‰

Reflect on a year of innovation, growth, & unwavering commitment to livable security with Santa and Workshop. Read about our journey and what's next! #FirstAnniversary #Santa #Workshop

northpole.security/blog/one-yea...

09.10.2025 17:45 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
a man in a suit says " don 't you think she looks tired " to another man in a suit ALT: a man in a suit says " don 't you think she looks tired " to another man in a suit
30.08.2025 14:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

m.media-amazon.com/images/I/71m...

03.08.2025 20:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Headed to hacker summer camp looking first to seeing people and sharing @northpolesec.bsky.social’s Workshop with people.

03.08.2025 14:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Tbh I did it because it seems to get the word out to folks who’ve split from Twitter, to Bluesky and mastodon.

LinkedIn seems to be one of the few common spots.

Also I’m stuck on the plane.

03.08.2025 14:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

In case you see me. Yes this is why I look so exhausted. πŸ˜‚

31.07.2025 16:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It's not just one release, it's two!

31.07.2025 16:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

It's been an 11 month journey to build Workshop, the integrated backend Santa always deserved

Lots of things we'd always wanted at Google are now real

The MVP's already powerful & we're just getting started

Thank you to Zane & the team at A16Z, Royal Hansen and the team @northpolesec.bsky.social

30.07.2025 14:48 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Santa FAA rule to prevent spotlight plugins from being registered Santa FAA rule to prevent spotlight plugins from being registered - sploitlight.md

I made this gist gist.github.com/pmarkowsky/9... to show how @northpolesec.bsky.social Santa FAA rules lockdown the Spotlight importers used in Sploitlight microsoft.com/en-us/securi... &
@theevilbit.bsky.social's persistence trick.

I also added an example rule for blocking access to the DBs.

29.07.2025 16:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Going to be attending @bsideslv.org and around. Summer camp.

If you’re around say hello.

24.07.2025 12:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This was a big release. Getting CEL in opens up so many possibilities and like all good things it's a take what you need.

Really looking forward to seeing what people do with this.

08.07.2025 13:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Lots of great features in 2025.5.

Santa is now easier to use without having to drop to the command line.

Be sure to check out the videos in the 🧡

29.05.2025 13:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It’s something that feels like the sci-fi future media promised us as kids

14.05.2025 10:07 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Yikes. Got any other FRs? Asking for a friend…

11.05.2025 19:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Have to admit it's exciting to see years of work coming together.

08.05.2025 14:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@plm is following 19 prominent accounts