HardenMac Free First-Response Checklist
Use this when you downloaded something questionable, noticed unusual behavior, found an unexpected process or background item, received an account alert, or no longer trust the Mac.
This checklist does not diagnose the device. It gives you the first moves in a safer order.
0. Stop and preserve context
Before deleting files, erasing the Mac, or changing critical passwords from the affected device:
- Write down what made you suspicious.
- Note the date and approximate time.
- Record recent installs, permission prompts, and admin-password requests.
- Take screenshots that do not reveal secrets.
- Record suspicious filenames, paths, process names, and security alerts.
- Do not run random cleanup commands from the internet.
- Do not install multiple new tools without a clear reason.
- Do not log in to critical accounts from the affected Mac.
1. Contain active behavior
If an unknown process is still running, activity is continuing, or data may still be leaving the Mac:
- Disconnect Wi-Fi.
- Unplug Ethernet.
- Safely eject and disconnect unneeded external drives when possible; do not connect additional drives.
- Stop using the Mac for account recovery.
If professional forensic help is imminent, avoid powering off or restarting until you receive instructions. For most individuals and small operators, containing active access and securing accounts from another device takes priority.
2. Move critical work to a trusted device
Use a separate device you have reason to trust: a phone or tablet, another updated computer not involved in the incident, or a freshly installed system.
From that device, begin with:
- primary and recovery email;
- password manager;
- Apple Account;
- banking, payment, and identity accounts;
- domain, DNS, hosting, and work-admin accounts;
- cloud storage and backups;
- AI tools, connected apps, and automation platforms; and
- developer accounts, API keys, and SSH keys where applicable.
3. Map what the Mac could reach
Browser and account exposure
- Which browsers and profiles were used?
- Were passwords, payment cards, or addresses stored?
- Were critical accounts already signed in?
- Were extensions installed with broad permissions?
- Was browser sync enabled?
Files and device exposure
- Which cloud drives were syncing?
- Were private documents, IDs, tax files, contracts, client files, or photos accessible?
- Were backups, network storage, or external drives available?
- Did the Mac have access to other computers or remote servers?
Business, AI, and developer exposure
- Were domain registrars, hosting, DNS, payment, commerce, ad, or analytics dashboards signed in?
- Were AI tools or agents connected to email, files, browser, GitHub, Notion, Drive, Slack, or other services?
- Were API keys, SSH keys, app passwords, tokens,
.envfiles, repositories, or deployment tools present?
4. Secure control accounts first
Provider workflows differ. Use each provider's current compromised-account or security instructions.
For critical accounts, handle the applicable actions as a pair:
- review sessions and devices;
- sign out other sessions where supported;
- remove unknown devices;
- change the password;
- review recovery email and phone;
- review 2FA methods, passkeys, and backup codes;
- revoke unknown or unnecessary connected apps; and
- rotate app passwords, API keys, tokens, and SSH keys where relevant.
Start with accounts that can reset or control other accounts:
- primary and recovery email;
- password manager;
- Apple Account or other identity provider;
- banking/payment and identity accounts;
- domain/DNS/hosting and work-admin accounts;
- cloud storage and backups;
- developer and deployment platforms;
- AI tools and automation platforms; and
- social and publishing accounts.
5. Decide cleanup, rebuild, or escalation
A limited review may be enough for a low-risk, explainable event. A clean rebuild is more strongly favored when:
- suspicious persistence exists;
- an unexpected system-level LaunchDaemon or elevated process is involved;
- unknown binaries ran;
- behavior repeatedly returned;
- you cannot explain what ran or for how long;
- high-value accounts, client data, financial assets, wallets, or developer keys may have been reachable; or
- you no longer trust the device state.
Use the Clean-Rebuild Decision Tree before erasing or restoring.
6. Do not blindly restore old machine state
A full system migration or backup restore may reintroduce old apps, browser profiles, hidden folders, launch items, Library content, scripts, or other untrusted state.
For serious trust loss, consider a documents-only restore:
- restore user-created files in reviewed batches;
- reinstall applications fresh from official sources;
- rebuild browser profiles and extensions carefully; and
- do not automatically migrate old apps, binaries, Library folders, launch items, shell profiles, automation configs, or system settings.
Documents can also contain risky active content. Review macros, scripts, archives, installers, and project automation before opening or running them.
7. Harden after recovery
- Keep macOS and browsers updated.
- Review extensions and connected apps regularly.
- Use a password manager and strong account recovery.
- Reduce browser-stored secrets.
- Separate high-risk testing from banking, email, and business administration.
- Keep API keys and tokens out of notes, desktops, screenshots, and synced project files.
- Consider reputable outbound monitoring and persistence alerts.
- Maintain a tested backup and clean-reinstall plan.
Final checkpoint
If the Mac could reach primary email, a password manager, financial accounts, identity documents, domain/DNS control, client systems, crypto keys, developer credentials, or broad AI agents, treat the event as an access exposure until the relevant sessions, permissions, recovery paths, and credentials have been reviewed.