Skip to content

Add macOS Software Signing cert to exclusions for macOS 27 - #6766

Merged
Mikaayenson merged 2 commits into
mainfrom
macos_golden_gate
Sep 12, 2026
Merged

Mikaayenson merged 2 commits into
mainfrom
macos_golden_gate

Conversation

@shashank-elastic

Copy link
Copy Markdown
Contributor

Pull Request

Issue link(s): NA

Summary - What I changed

  • macOS 27 renames Apple's platform binary signing certificate CN from "Software Signing" to "macOS Software Signing", this adds the new CN alongside the old one in the affected rules to prevent false positives on Golden Gate hosts.

How To Test

Checklist

  • Added a label for the type of pr: bug, enhancement, schema, maintenance, Rule: New, Rule: Deprecation, Rule: Tuning, Hunt: New, or Hunt: Tuning so guidelines can be generated
  • Added the meta:rapid-merge label if planning to merge within 24 hours
  • Secret and sensitive material has been managed correctly
  • Automated testing was updated or added to match the most common scenarios
  • Documentation and comments were added for features that require explanation

Contributor checklist

@shashank-elastic shashank-elastic self-assigned this Sep 11, 2026
Copilot AI lite review requested due to automatic review settings September 11, 2026 06:10
@shashank-elastic shashank-elastic added Rule: Tuning tweaking or tuning an existing rule currentrelease labels Sep 11, 2026
@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Sep 11, 2026

Copy link
Copy Markdown

⛔️ Test failed

Results
  • ❌ Unusual Network Connection to Suspicious Web Service (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The reviewed change is focused and addresses the stated macOS 27 compatibility need.

Pull request overview

Updates a macOS detection rule to recognize Apple’s macOS 27 signing certificate name and prevent false positives.

Changes:

  • Adds macOS Software Signing to trusted signer exclusions.
  • Updates the rule metadata date.
File summaries
File Description
rules/macos/command_and_control_unusual_network_connection_to_suspicious_web_service.toml Adds the new macOS signing certificate exclusion.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@eric-forte-elastic eric-forte-elastic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this was in 26.6 as well: https://eclecticlight.co/2026/07/27/what-has-changed-in-macos-tahoe-26-6/

Looks good 👍

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Sep 12, 2026

Copy link
Copy Markdown

⛔️ Test failed

Results
  • ❌ Unusual Network Connection to Suspicious Web Service (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta

@Mikaayenson
Mikaayenson added this pull request to the merge queue Sep 12, 2026
Merged via the queue into main with commit 91b3aac Sep 12, 2026
10 checks passed
@Mikaayenson
Mikaayenson deleted the macos_golden_gate branch September 12, 2026 01:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants