Skip to content

Version 2.2.0

Latest

Choose a tag to compare

@objective-see objective-see released this 05 Aug 18:41

πŸ†• You can now sponsor RansomWhere?/Objective-See Foundation:

RansomWhere? v2.2.0

This release brings macOS 27 (beta) compatibility, along with various fixes and improvements! πŸ₯³

β˜‘οΈ macOS 27 support: installer now removes the quarantine attribute from installed components (macOS 27's launchd won't load quarantined launch daemon plists)
β˜‘οΈ Improved monitoring: interpreters & script hosts are never muted, so rules/mutes for one script can no longer blind monitoring of an interpreter's future scripts
β˜‘οΈ Improved file analysis: files with degenerate stats (e.g. truncated mid-analysis) are no longer misclassified as encrypted
β˜‘οΈ Improved alerts: encrypted-file list is now a consistent (race-free) snapshot, and the process hierarchy is ordered correctly
β˜‘οΈ Bug fixes: rules window now refreshes after creating a rule via an alert, invalid bundles/paths in rules are gracefully handled, and the signing info popover shows the correct "platform binary" value
β˜‘οΈ Hardening: XPC clients must have a valid signature and hardened runtime, file ownership set via lchown (symlinks never followed), plus cleaner daemon startup/teardown
β˜‘οΈ Cleanup: removed unused code, improved error handling & logging

πŸ” Zip (SHA256):
RansomWhere_2.2.0.zip: 982B0B9C3027947E0AACA16D7936FE3E6639DDABE8FAFE979C50C7D8C4302AF1