Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 8 checks on this page
- 6.1 Finder
- Ensure Show All Filename Extensions Is Enabled
- 6.3 Safari
- Ensure Automatic Opening of Safe Files in Safari Is Disabled
- Ensure Safari Advertising Privacy Protection Is Enabled
- Ensure Safari Prevents Cross-Site Tracking
- Ensure Safari Shows the Full Website Address
- Ensure Safari Status Bar Is Shown
- Ensure Safari Warns When Visiting a Fraudulent Website
- 6.4 Terminal
- Ensure Terminal Secure Keyboard Entry Is Enabled
6.1 Finder
Ensure Show All Filename Extensions Is Enabled
Finding: Show all filename extensions is disabled.
Checks the Finder per-user setting that forces all filename extensions to be shown.
This rule fails when showAllExtensions is not true for a Finder user-settings object.
Rationale: Hidden extensions let a file masquerade as a benign type, aiding social-engineering and malware delivery.
Impact: Filenames display their true extension for every file.
Remediation
In Finder > Settings > Advanced, enable Show all filename extensions.
From the command line:
/usr/bin/sudo -u <username> /usr/bin/defaults write /Users/<username>/Library/Preferences/.GlobalPreferences.plist AppleShowAllExtensions -bool true
- Framework mappings
- CIS Controls v8: 2.3 Address Unauthorized Software
- NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-8 System Component Inventory; CM-10 Software Usage Restrictions; CM-11 User-installed Software
- PCI DSS v4.0.1: 12.3.4 Annually assess whether hardware and software in use remain supported
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Execution (TA0002)
6.3 Safari
Ensure Automatic Opening of Safe Files in Safari Is Disabled
Finding: Safari automatically opens safe files after download.
Checks the Safari per-user setting that auto-opens files deemed safe after download.
This rule fails when autoOpenSafeDownloads is not false for a Safari user-settings object.
Rationale: Auto-opening downloads can trigger malicious payloads without user action.
Impact: Downloaded files must be opened manually by the user.
Remediation
Install a configuration profile with PayloadType com.apple.Safari and set AutoOpenSafeDownloads to false.
- Framework mappings
- CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.6 Block Unnecessary File Types
- NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code; SI-3 Malicious Code Protection; SI-8 Spam Protection
- PCI DSS v4.0.1: 5.4.1 Detect phishing attempts and shield personnel through automated defenses
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Safari Advertising Privacy Protection Is Enabled
Finding: Safari privacy-preserving ad measurement is disabled.
Checks the Safari privacy-preserving ad-click measurement (PCM) setting.
This rule fails when privateClickMeasurement is not true for a Safari user-settings object.
Rationale: PCM measures ad effectiveness without exposing individual user browsing to advertisers.
Impact: Ad attribution runs in a privacy-preserving manner.
Remediation
Install a configuration profile with PayloadType com.apple.Safari and set WebKitPreferences.privateClickMeasurementEnabled to true.
Ensure Safari Prevents Cross-Site Tracking
Finding: Safari cross-site tracking prevention is not fully enabled.
Checks the three Safari storage-blocking policies that together prevent cross-site tracking.
This rule fails when blockStoragePolicy is not BLOCK_ALL or either WebKit storage-blocking policy is not BLOCK_THIRD_PARTY.
Rationale: Third-party storage is the primary mechanism for cross-site tracking of users.
Impact: Cross-site trackers can no longer persist storage between sites.
Remediation
Install a configuration profile with PayloadType com.apple.Safari: set BlockStoragePolicy to 2, WebKitPreferences.storageBlockingPolicy to 1, and WebKitStorageBlockingPolicy to 1.
Ensure Safari Shows the Full Website Address
Finding: Safari does not show the full website address.
Checks the Safari setting that shows the complete URL in the address bar.
This rule fails when showFullURL is not true for a Safari user-settings object.
Rationale: Showing the full URL helps users spot look-alike or deceptive phishing domains.
Impact: The address bar shows the complete URL instead of only the domain.
Remediation
Install a configuration profile with PayloadType com.apple.Safari and set ShowFullURLInSmartSearchField to true.
- Framework mappings
- CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Safari Status Bar Is Shown
Finding: Safari status bar is hidden.
Checks the Safari setting that shows the status bar revealing link destinations on hover.
This rule fails when showStatusBar is not true for a Safari user-settings object.
Rationale: The status bar reveals a link's true destination before the user clicks, exposing deceptive links.
Impact: Hovering a link shows its destination in the status bar.
Remediation
Install a configuration profile with PayloadType com.apple.Safari and set ShowOverlayStatusBar to true.
- Framework mappings
- CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Safari Warns When Visiting a Fraudulent Website
Finding: Safari fraudulent-website warning is disabled.
Checks the Safari per-user setting that warns before loading known phishing or malware sites.
This rule fails when warnFraudulentWebsites is not true for a Safari user-settings object.
Rationale: The warning is a first-line defense against phishing and drive-by malware sites.
Impact: Safari displays a warning interstitial for known fraudulent sites.
Remediation
Install a configuration profile with PayloadType com.apple.Safari and set WarnAboutFraudulentWebsites to true.
- Framework mappings
- CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.3 Maintain and Enforce Network-Based URL Filters
- NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-7 Boundary Protection; SC-18 Mobile Code
- PCI DSS v4.0.1: 1.2.6 Add security features that offset risk from active insecure services; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Initial Access (TA0001)
6.4 Terminal
Ensure Terminal Secure Keyboard Entry Is Enabled
Finding: Terminal Secure Keyboard Entry is disabled.
Checks Terminal.app Secure Keyboard Entry, which blocks other apps from intercepting keystrokes.
This rule fails when terminalSecureKeyboardEntry is not true for a Terminal user-settings object.
Rationale: Without Secure Keyboard Entry, other processes can capture keystrokes (including passwords) typed in Terminal.
Impact: Other applications can no longer read keystrokes entered in Terminal.
Remediation
Install a configuration profile with PayloadType com.apple.Terminal and set SecureKeyboardEntry to true.
From the command line:
/usr/bin/defaults write -app Terminal SecureKeyboardEntry -bool true
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)