HardenMac First-Response Self-Check

Free · Companion to the checklist

HardenMac First-Response Self-Check

This self-check is a triage aid, not a diagnosis. It separates evidence that something may be wrong from the amount of access the Mac held. A heavily used Mac is not automatically compromised, but the same warning sign matters more when high-value access is present.

Mark each item Yes / No / Unsure.

A. Trigger signals

  1. Did you recently install an app, script, extension, model runner, helper, cracked app, or utility from a source you do not fully trust?
  2. Did the Mac begin behaving unusually after an install, permission prompt, or admin-password request?
  3. Did a security tool flag a file, process, persistence item, or credential-stealer family?
  4. Did you notice account activity, password-reset messages, new devices, or sign-ins you do not recognize?
  5. Did you find a process, hidden folder, login item, background item, LaunchAgent, or LaunchDaemon you cannot explain?

B. Persistence and active-behavior signals

  1. Did suspicious behavior survive a restart?
  2. Did a process return after being stopped?
  3. Did an Apple-like or system-like name appear in an unexpected location?
  4. Was an unexpected process running with elevated or root privileges?
  5. Were logs suppressed, redirected, missing, or written to /dev/null?
  6. Did you observe unexplained outbound network activity, remote-control behavior, or continuing changes?

C. Access surface

  1. Was primary or recovery email signed in?
  2. Was your Apple Account or iCloud Keychain available?
  3. Was a password manager unlocked or accessible?
  4. Were browser profiles signed in or storing passwords, cookies, or payment details?
  5. Were banking, payment, domain, hosting, work-admin, client, or identity accounts accessible?
  6. Were cloud drives, backups, external drives, or private documents available?
  7. Were AI tools or agents connected to email, files, code, browser, or cloud accounts?
  8. Were API keys, SSH keys, app passwords, tokens, .env files, or developer credentials present?

D. Stakes and escalation

  1. Could the incident involve regulated, client, customer, employee, student, patient, legal, or tax data?
  2. Could it involve meaningful money movement, crypto wallets, signing keys, or identity theft?
  3. Could it affect business-critical infrastructure or other devices?
  4. Is there evidence of active unauthorized access or financial fraud?

Triage result

Preparation / low immediate concern

Use this path only when:

Next steps: complete the Mac Hardening Checklist, review browser extensions and connected apps, and pre-fill the tracker workbook.

Moderate concern

Use this path when at least one trigger is Yes or Unsure, but there is no clear persistence, active remote behavior, or unauthorized account activity.

Next steps:

High concern

Treat the situation as high concern if any of the following is Yes:

Next steps: follow the First-Hour Protocol immediately, disconnect the affected Mac from the network if suspicious activity appears active, and consider qualified incident-response help.

Exposure escalator

The Access Surface section does not prove compromise. It determines the scope of recovery. If primary email, password manager, financial accounts, identity records, business control accounts, client systems, crypto keys, or developer secrets were reachable, increase the urgency and depth of the response even when evidence is incomplete.

HardenMac is experience-based guidance, not professional advice, and not antivirus or incident response. It does not scan this Mac, its accounts, files or network, and it cannot detect or rule out a problem. Menu names vary by macOS version; if a setting has moved, search for its name inside System Settings.