X World 2026

25-26 AUGUST • NAARM | MELBOURNE

Victor Lyuboslavsky

Victor Lyuboslavsky

Building an Open Source macOS EDR: Lessons From Apple's Endpoint Security Framework

Every modern macOS EDR (Endpoint Detection and Response) is an Endpoint Security client. Whatever vendor name is on the agent, they all subscribe to the same Apple framework underneath. The Endpoint Security Framework is the feed that makes a macOS EDR possible. Its limits are the limits of every EDR built on it. This session goes inside that framework. We walk through what ESF actually emits: exec, fork, exit, open, and the distinction between notify and auth events. We then cover what an EDR can block versus only observe, the entitlement gauntlet to ship a system extension, and the performance trap that can put a Mac on its knees. The tour is grounded in an open-source macOS EDR built on ESF. Every architectural choice and gotcha applies to any vendor's product. Attendees will leave able to answer practical questions. When a vendor says "we monitor process execution," what specifically does that mean? When they say "we can block," which subset of events did they actually subscribe to? And what does an ESF-based agent actually need from your MDM?

About the presenter

Victor Lyuboslavsky is a software engineering leader, author, and speaker with over 25 years of experience building products and leading teams. He has co-founded startups, held technical leadership roles at AMD, and now architects secure, scalable systems for enterprise IT at Fleet Device Management, covering fleets of macOS, iOS, and other major platforms. Victor's work bridges hands-on technical execution and strategic leadership. His talks draw on lessons from startups, open source communities, and creating an open source macOS EDR, with a focus on Apple platform security, hardware-backed identity, and endpoint telemetry.

SPONSORS & PARTNERS