github objective-see/RansomWhere v2.2.0
Version 2.2.0

3 hours ago

🆕 You can now sponsor RansomWhere?/Objective-See Foundation:

RansomWhere? v2.2.0

This release brings macOS 27 (beta) compatibility, along with various fixes and improvements! 🥳

☑️ macOS 27 support: installer now removes the quarantine attribute from installed components (macOS 27's launchd won't load quarantined launch daemon plists)
☑️ Improved monitoring: interpreters & script hosts are never muted, so rules/mutes for one script can no longer blind monitoring of an interpreter's future scripts
☑️ Improved file analysis: files with degenerate stats (e.g. truncated mid-analysis) are no longer misclassified as encrypted
☑️ Improved alerts: encrypted-file list is now a consistent (race-free) snapshot, and the process hierarchy is ordered correctly
☑️ Bug fixes: rules window now refreshes after creating a rule via an alert, invalid bundles/paths in rules are gracefully handled, and the signing info popover shows the correct "platform binary" value
☑️ Hardening: XPC clients must have a valid signature and hardened runtime, file ownership set via lchown (symlinks never followed), plus cleaner daemon startup/teardown
☑️ Cleanup: removed unused code, improved error handling & logging

🔐 Zip (SHA256):
RansomWhere_2.2.0.zip: 982B0B9C3027947E0AACA16D7936FE3E6639DDABE8FAFE979C50C7D8C4302AF1

Don't miss a new RansomWhere release

NewReleases is sending notifications on new releases.