HardenMac First-Response Self-Check
This self-check is a triage aid, not a diagnosis. It separates evidence that something may be wrong from the amount of access the Mac held. A heavily used Mac is not automatically compromised, but the same warning sign matters more when high-value access is present.
Mark each item Yes / No / Unsure.
A. Trigger signals
- Did you recently install an app, script, extension, model runner, helper, cracked app, or utility from a source you do not fully trust?
- Did the Mac begin behaving unusually after an install, permission prompt, or admin-password request?
- Did a security tool flag a file, process, persistence item, or credential-stealer family?
- Did you notice account activity, password-reset messages, new devices, or sign-ins you do not recognize?
- Did you find a process, hidden folder, login item, background item, LaunchAgent, or LaunchDaemon you cannot explain?
B. Persistence and active-behavior signals
- Did suspicious behavior survive a restart?
- Did a process return after being stopped?
- Did an Apple-like or system-like name appear in an unexpected location?
- Was an unexpected process running with elevated or root privileges?
- Were logs suppressed, redirected, missing, or written to
/dev/null? - Did you observe unexplained outbound network activity, remote-control behavior, or continuing changes?
C. Access surface
- Was primary or recovery email signed in?
- Was your Apple Account or iCloud Keychain available?
- Was a password manager unlocked or accessible?
- Were browser profiles signed in or storing passwords, cookies, or payment details?
- Were banking, payment, domain, hosting, work-admin, client, or identity accounts accessible?
- Were cloud drives, backups, external drives, or private documents available?
- Were AI tools or agents connected to email, files, code, browser, or cloud accounts?
- Were API keys, SSH keys, app passwords, tokens,
.envfiles, or developer credentials present?
D. Stakes and escalation
- Could the incident involve regulated, client, customer, employee, student, patient, legal, or tax data?
- Could it involve meaningful money movement, crypto wallets, signing keys, or identity theft?
- Could it affect business-critical infrastructure or other devices?
- Is there evidence of active unauthorized access or financial fraud?
Triage result
Preparation / low immediate concern
Use this path only when:
- every trigger signal is No;
- every persistence or active-behavior signal is No; and
- there is no unrecognized account activity.
Next steps: complete the Mac Hardening Checklist, review browser extensions and connected apps, and pre-fill the tracker workbook.
Moderate concern
Use this path when at least one trigger is Yes or Unsure, but there is no clear persistence, active remote behavior, or unauthorized account activity.
Next steps:
- stop using the affected Mac for critical accounts;
- move account review to a trusted device;
- follow the First-Hour Protocol;
- review sessions and connected apps; and
- use the Clean-Rebuild Decision Tree.
High concern
Treat the situation as high concern if any of the following is Yes:
- unexpected persistence;
- repeated relaunch behavior;
- unexpected elevated/root execution;
- security-tool detection of a stealer, backdoor, or remote-access tool;
- unauthorized account activity;
- evidence of active exfiltration or remote control.
Next steps: follow the First-Hour Protocol immediately, disconnect the affected Mac from the network if suspicious activity appears active, and consider qualified incident-response help.
Exposure escalator
The Access Surface section does not prove compromise. It determines the scope of recovery. If primary email, password manager, financial accounts, identity records, business control accounts, client systems, crypto keys, or developer secrets were reachable, increase the urgency and depth of the response even when evidence is incomplete.