{"id":"8724581a-8411-4390-88cc-bb489e1fa40c","slug":"null-event-macos-detect-and-respond-skills","name":"macos-detect-and-respond","description":"Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts.","canonicalUrl":"https://www.xpersona.co/skill/null-event-macos-detect-and-respond-skills","sourceUrl":"https://github.com/null-event/macos-detect-and-respond-skills","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"null-event","label":"Null Event","url":"https://github.com/null-event/macos-detect-and-respond-skills"},"protocols":["OPENCLEW"],"capabilities":["cause"],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-04-15T03:15:56.674Z","freshnessLabel":"Apr 15, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Apr 15, 2026"},{"label":"Vendor","value":"Null Event"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"docs_crawl","label":"Crawlable docs","value":"6 indexed pages on the official domain","category":"integration","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true,"metadata":{}},{"factKey":"vendor","label":"Vendor","value":"Null Event","category":"vendor","href":"https://github.com/null-event/macos-detect-and-respond-skills","sourceUrl":"https://github.com/null-event/macos-detect-and-respond-skills","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T03:15:56.674Z","isPublic":true,"metadata":{}},{"factKey":"protocols","label":"Protocol compatibility","value":"OpenClaw","category":"compatibility","href":"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-04-15T03:15:56.674Z","isPublic":true,"metadata":{}},{"factKey":"handshake_status","label":"Handshake status","value":"UNKNOWN","category":"security","href":"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/null-event-macos-detect-and-respond-skills/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true,"metadata":{}}],"highlights":["Trust evidence available"],"agentCard":{"name":"macos-detect-and-respond","description":"Assists with macOS security detection engineering including writing detections for Endpoint Security events, translating adversary behaviors to queries (Splunk/osquery/Sigma), analyzing macOS telemetry, mapping to ATT&CK, and triaging alerts.","source":"GITHUB_OPENCLEW","sourceId":"github:1137644028","repository":"https://github.com/null-event/macos-detect-and-respond-skills","documentation":"https://www.xpersona.co/skill/null-event-macos-detect-and-respond-skills/agent/null-event-macos-detect-and-respond-skills","protocols":["OPENCLEW"],"capabilities":["cause"],"languages":["typescript"],"install":{"command":"git clone https://github.com/null-event/macos-detect-and-respond-skills.git","ecosystem":"git"},"examples":[{"kind":"example","language":"spl","snippet":"index=macos sourcetype=\"esf:json\" event_type=\"ES_EVENT_TYPE_NOTIFY_EXEC\"\n| where isnull('process.signing_id') OR 'process.signing_id'=\"\"\n| where match('process.executable.path', \"^/tmp/\")\n| table _time, host, user, process.executable.path, process.cmdline, process.parent.name"},{"kind":"example","language":"text","snippet":"Suspicious indicators:\n- Unsigned or ad-hoc signed\n- Execution from /tmp, /var/tmp, ~/Downloads\n- Unusual parent-child relationship\n- Suspicious command-line arguments (curl | bash, base64, etc.)\n- Network activity immediately after execution"}]}}