6 min read
|
Saved February 14, 2026
|
Copied!
Do you care about this?
MacPersistenceChecker is a macOS app that identifies all items set to run automatically on your system. It helps detect malware and unwanted software by scoring each persistence mechanism based on risk factors. Users can analyze and decide what to keep or remove.
If you do, here's more
MacPersistenceChecker is a security tool for macOS that identifies and analyzes software configured to launch automatically. Designed for macOS 13.0 or later, it scans various persistence mechanisms, such as Launch Daemons, Launch Agents, Login Items, and more. Each item is evaluated for risk, producing a score from 0 to 100 based on factors like code signatures, file locations, and known malware patterns. The tool categorizes threats into severity levels, helping users identify potential risks quickly.
The software tracks over 40 living-off-the-land binaries (LOLBins), mapping them to the MITRE ATT&CK framework for a clearer understanding of their behavior and potential threats. Advanced heuristics detect suspicious patterns, such as hidden persistence guards or orphaned persistence items, and it can identify discrepancies between what a configuration file declares and the actual behavior of a binary. MacPersistenceChecker also monitors for malicious updates, detecting patterns like silent binary swaps and timestamp manipulations.
Users receive a detailed analysis of installed applications, scoring them based on their persistence mechanisms and potential "junk" footprint. The tool provides visual representations of risk distributions, trust levels, and item lifecycles. Continuous monitoring is possible through real-time file system tracking, ensuring that any changes in persistence mechanisms are flagged. Overall, MacPersistenceChecker equips users with the tools needed to manage their macOS environments proactively, identifying and mitigating potential security threats effectively.
Questions about this article
No questions yet.