Skip to content

macos-mscp-scan v0.4.0

Latest

Choose a tag to compare

@r4kh1m r4kh1m released this 09 Aug 20:42
v0.4.0
bfc4525

This release refines the default personal baseline after an end-to-end review on a personally administered Mac. It reduces organization-specific noise, checks more effective local state, and fixes result-contract mismatches that could misclassify a passing check as a finding.

Highlights

  • Excludes traditional auditd, forensic logging, global CIS password-policy, fixed organization time-server, and selected privacy-choice controls from the default personal scope.
  • Uses effective local state for App Store updates, Terminal Secure Keyboard Entry, Bluetooth Sharing, password hints, Remote Apple Events, and SMB.
  • Accepts Firewall Block All as enabled and checks screen locking in the active user's context.
  • Accepts a sudo credential-cache timeout from zero through two minutes.
  • Validates mSCP numeric result contracts to prevent false findings.

The personal profile remains a security-posture audit, not a CIS Benchmark assessment. Excluded rules are outside scope, not passes.

Validation

Shell syntax, interface tests, full preparation smoke testing, signed archive verification, and an authorized read-only macOS 26 Apple Silicon audit passed. The audit completed with 48 applicable checks passed, zero findings, and one architecture-appropriate N/A for Power Nap.

See the complete release and verification notes.