Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Apple Endpoint Telemetry with Jamf Protect

Jamf
08/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


with Apple Telemetry. And we're joined by Scott and Thomas, who's going to go through that for us. So I'm going to hand it over to them. Thank you so much for the intro. Welcome, everybody. I hope you're getting excited for this presentation. Our goal with me and Scott is to leave you with some basic information about the signal and the signal sources, how to work with those signals, and how to use them practically in your jobs. My name is Tomas. I work as a manager of product owners. I work with Jamf Protect engineering teams in endpoint security domain. And Scott is a senior sales engineer. All right, before we dive in into the agenda, it's pretty packed with a lot of information for you. I just wanted to ask you some questions. First one would be, who has, in the room, already experienced with telemetry? All right, and please keep your hands if you were successful with the telemetry, if you are. OK, not so much. And the last question, how many of the people here are administrators, Mac admins, and which are security folks? So who's Mac admin? Yeah, sorry, Mac admins. Yeah, sorry, I was too fast. OK, yeah, less folks. All right, so let's go for the agenda. So first of all, we would like to talk about what the telemetry is and what it isn't. Then we will provide some easy setup guide for you to try. And we will finish up with some tips and tricks and gotchas. So let's go. So let's have a look, and let's start how the telemetry might look like and what is it. So let's think about some ordinary day with some seemingly ordinary user. So this user, yeah, let's call him Scott. He logs in. He puts encrypted USB. Some malicious script gets blocked. Yeah, the user elevated the rights to admin. Pseudo command is executed. Alert, there is a suspicious curl. Get the perk override by Scott. TCC for this access. Network connection, persistence, app performance metrics and crash report. Yeah, some file doc printing by Scott. Yeah, and lots of other things. OK, so it's pretty busy for such an ordinary day. And yeah, some of the stuff we saw on the timeline was blocked. And this is for the security tools to do this job. But blocking these things isn't the same thing as having the visibility. And that's the gap that telemetry is closing. So yeah, I would like to ask now, Scott, to tell us more technically what the telemetry is. Yeah, perfect. Thank you. Can everyone hear me all right? Is that coming through? Yeah, perfect. So yeah, Thomas gave us a great explanation around what we could collect with telemetry. But also, what is it? Because it's not actually something that we've built. It's actually built into the operating system itself. But under the hood, there's a few other key parts to that. So the three key components are we've got the Apple Endpoint Security Framework. So I'm going to hope that most of you are on a very recent OS, shall we say, in the last couple of years, right? If you are, then you're probably going to have the Endpoint Security Framework on this. From there, we use that data, something called ES Logger on a device. You can test this yourself. Again, if you're going to terminal, you do ES Logger. There's a kind of man page for it. And it will give you how to run it. That will spit back out telemetry data, or that will spit out ES Logger data that we then take. And we, at Jamf Protect, serialize that JSON and make it a little bit prettier and easier to read for you to put into another tool. So again, like I say here, we're not actually running anything on the device itself. We're monitoring that ES Logger tool, and then pulling that out, making it easier to read and understand before sending it to your endpoint. So that JSON structure, what does it actually look like? Well, again, there's a few key parts to it. The first part is an event. So basically, we collect events. Think of this like categories, or maybe like in music, like a genre. In there, you've got rock, you've got pop, and then there are different types of styles below that. But an event, basically, is something happening on the device. So who here runs Jamf Pro on their machines? Yeah, perfect. Who here has issues monitoring for binary removals or the binary not installing correctly? Yeah, a few hands going up. I know there's more than that, because these are emailing me every single day, so don't be shy. So what I'm going to do here, again, because we're focusing on telemetry, I thought I'd pick an easy thing that everyone would understand. Here, I'm just going to quickly delete the actual Jamf binary. Now, what you'll see is, again, I'm going to get an authorization prompt and all that. So great, perfect. In the background, you might have noticed that there was things happening here. I've got a little tool that could monitor for that telemetry stuff. So again, what we're going to look at is what this looks like on the device before we then send it to SIEM as well. So I've now removed the Jamf binary. What that gave us is, from that one event of the deletion, it's given us lots of different JSON. But the thing that we are looking at just now is that event type. So as I said earlier, this is the key thing of what we're logging initially at the top level. So we want to monitor for those specific event types. So this one here is coming from an analytic. But basically, you get various different ones as well. So this one here is a GPFS event, basically, a file system event. Again, don't worry too much about the rest of it, and we'll come on to what that looks like. But if you're wondering how much data there is, just for that one deletion command, it looks a bit like this. So there's a fair bit of data in there. So again, that's just the one command. There's more that you've seen in the background happening there, which we'll come on to. But in terms of these event types, there is actually so many that I couldn't fit them all on the board here. So definitely go to our documentation if you want to find out what they all are. But there's a few useful ones in there, specifically the ones that I like are around screen sharing. So again, you can find out when somebody's screen sharing session is attached and detached. That can be useful for both support and also monitoring for security issues. Profile, you can find out when an MDM profile has been installed or removed. So again, if you're wanting live, real-time reporting, obviously, you can collect that in Jamf Pro. But you can also monitor for it with telemetry. Again, really useful for troubleshooting. If a profile gets removed from a machine that might be crucial, you could actually start to build workflows around that. And again, one of the other ones that I really like, Apple recently just added this. I think it was not Tahoe, but Sequoia before that, was the TCC Modify. It's somewhere on here. Yes, I put it down here in the corner so I can point to it quickly. TCC Modify, basically, if you think about any time that a user gets prompted to enable a security setting, like potentially something want access to the location, it may want access to a file and folder, that actually gets logged in telemetry as TCC Modify. So you can actually monitor for that. So every time somebody enables microphone access or camera access, again, you can start to monitor for that as well. And again, none of these things are necessarily malicious things that are going on in the background. Again, you can absolutely do that with telemetry. The things I love to work around with telemetry are those support workflows. Like I say, again, I don't know, was anyone in Armin's onboarding workflow workshop this morning? Yeah? He talked about setup checklist. And with that, if you think about it, if somebody gets a new device and then instantly opens up Teams and disables the camera, the first thing they're going to do is they're going to call your help desk and say, oh, my Teams isn't working. And you're kind of going, well, is it installed? Is it on the machine? Is it not? With telemetry, you can actually log all that type of event. So you could monitor for the application install. And then you can monitor for them disabling the camera and potentially be a bit more proactive around that support workflow as well. So really useful from that point of view. The second part of the JSON objects is message. So this is what all that other data was. And depending on the event type will depend on what type of messages and what content's included in that. But some nice information that you will get is you'll get information around the host. So you can get things like the serial number, the logged in user, the Mac OS version that they're running, the Jamf Protect version that they're running, all these types of events when we trigger it. You'll also get some other process events as well within that. So if I just go back to this video now, again, thing to watch out for here is in the top corner. Watch all the streaming type things here. You'll see in the background, even before I do anything, it's starting to collect data. I will then go and delete that. It will remove the Jamf binary. We get that alert. But I also got that authentication prompt as well there. So again, if we look, we can also get that as part of that message. So just without anything running on a device, this is what that JSON message would look like. This is the structure of it. So if you're wondering how to break it down and where you want to go, this is it. The key parts for me, again, are the event, because that's the event type. What do we want to monitor for? And then you've got the host and the process. That's some of the key things that we're looking out for here. But with that authorization, this is what it looks like as well. So again, I get that event type. And that would be the authentication part there. So again, I appreciate it's small. But don't worry, we've got a few other examples. And with that authentication, what I can then do is I can scroll down a little bit. And in here, I'll actually start to see who authenticated it. Were they part of a specific group? How did they authenticate it? I can get it, whether it was processed by Touch ID, whether it was username and password. I can get all this type of data. Now, some of it is binary, so it'll be like zeros and ones. Other is actual text. Again, we're not going to go into that today. But there is documentation on what all the different event types and messages are in there. So if there is something that you are looking for, I'd recommend heading to our documentation before you just turn this on, because it will not be human-readable, to put it nicely. So Thomas, tell us more about Mac telemetry. Yeah, thank you so much. I hope by now that we all know at least the basics about the telemetry, what it is. I would like to provide you with more information, what it can do for you. So first of all, it's a much smoother experience. So thanks to the Apple framework, instead of legacy scanning agents that compete for resources. So that's the one thing. It provides compliance evidence. So yeah, that's what the auditors want, the audit trail. Visibility into unauthorized software, so you know what's running and not just what's being installed. Yeah, for the security folks, then it's the security event auditing, user override tracking, and yeah, of course, the threat hunting and faster incident response. Yeah, telemetry provides the full information. It's not just an alert. OK, let me get one thing clear. Telemetry isn't defense. There are other tools for that, for instance, EDR. So telemetry just sees what your security tools are missing. So yeah, it tells you the full story of what happened before, during, and after. OK, Scott, please tell us what happens if there is too many telemetry points. So again, on the why part of telemetry, because I imagine a lot of you are already questioning, like, we already have MDM, right? Like, not really seeing a difference. Some of the key points to that, as you've already seen, is that if you do use this wrong note, it can be a lot of noise. So again, if you already have MDM, you might be collecting some of this stuff. Think about what that enhances to your MDM knowledge. So again, things like the TCC modify that we can't collect as part of Jamf Pro, you should use telemetry for that. If it's just for application installs, maybe you don't need that straightaway, because we're already monitoring that in another tool. And again, when I say it can be a lot of noise, just the other week, we were at InfoSec. We had a demo device running, and it created 9,000 events in under three days. So if you're going in and turning everything in telemetry on, it's going to cost you a fair bit of money, because again, we're going to start streaming this all to a seam. So again, think about what it is that you want to collect. This was a device that wasn't even active all the time. So again, even in the background, when your device is hibernating, we still collect that telemetry data, because it might be doing stuff in the background, maybe waking up to check software updates, et cetera, and things like that. So if you, again, have MDM, you're already collecting stuff, recommendation is to think what could you potentially collect better as part of telemetry. So the setup, who here has a telemetry setup? I know Thomas asked this earlier, just another recap. One, two, two people. Either everyone's really shy, three people, maybe three, I see another hand. Everyone's really shy, or nobody wants to set it up. So there's a few different ways that you can set it up. The most common one, like I say, is that HTTPS endpoint. Think of your Splunks, your Sentinels, those types of things, that'll be one way. The other is you can also go via Jamf Protect Cloud and put it into cold storage, like an S3 bucket, if you want it for investigatory purposes later. And then there's a third element that most people don't look at, and that's something we want to dig in more today, is you can actually stream telemetry to a local log file on the Mac. So if you're testing or you want people in your organization to understand telemetry, to see the benefits, you can actually run it locally on a Mac to gather that data. And we'll come on to show you what that looks like. So again, HTTP endpoint, this is the perfect one for your security team. They've probably already got something like this set up, collecting other data. Again, we can plug into it. We've got playbooks for Splunk and Microsoft Sentinel and Datadog and so many more. The list goes on and on. But you'll be able to build pretty dashboards like this where you can stream that data to. Again, you can also just put it in a folder, in an S3 bucket if you want, or another cold storage system if you have something else, we can just stream directly to that as well. You would just get those raw JSON events as files. And then the other one is this log file, like I say. So this here, you can actually stream to a device. And today... Dyma lle byddwn ni'n gobeithio. Rwy'n meddwl bod llawer o bobl eisiau dechrau gyda'r telemetru. Efallai y dydych chi'n dweud, nid oes gen i sîm, nid oes gen i gysylltiad â sîm, nid yw'r sîm ar gyfer fi. Mae yna llawer o bobl yn y stryd, rwy'n gweld ychydig o'u nodi. Felly bydd y ffail lleol yma'n ddefnyddiol i helpu'r defnydd o, os oes gennym sîm neu ddim, rydym yn meddwl am gael un. Beth allwn ni ei wneud? Felly dyma'r gwahanol fathau o ddifrifnau y gallwch chi ddewis i'w gynhyrchu yn Jamf Protect Telemetry. Ac nid yw'n rhoi Thomas ar ôl y bus. Rwy'n credu ein bod ni'n gwneud hyn yn ychydig mwy grannol yn y ddatblygiad diwethaf yn ddiweddar y blynyddoedd y flwyddyn nesaf. Felly dydyn ni'n cael ddifrifnau sy'n lefel go iawn heddiw. Unwaith eto, ddatblygiadau, cyfathrebu a chynhyrchu, a chyfathrebu. Ond yn y dyfodol, byddwch chi'n gallu defnyddio cyfathrebu a chynhyrchu Felly, i ddatblygu'r logfail lleol, mae'n rhaid i ni ddewis y categorïau y byddwn ni eisiau eu cyfathrebu. Yn y ddyfodol hon, byddwn i'w ddefnyddio i gyd. Dydw i ddim yn argymell eich bod chi'n ei wneud hyn, ond gallwch chi'i ddefnyddio i gyd os ydych chi'n eisiau. Yn y dyfodol, nid yw'r cyfathrebu'n unig yn rhoi'r cyfathrebu i'r debyg. Felly mae'n rhaid i chi greu gweithle yn Jamf Protect hefyd. Yn y dyfodol, gallwch chi ddewis beth i'w cyfathrebu a lle i'w cyfathrebu. Felly, fel rhan o'r cyfathrebu cyfathrebu, gallwch chi ei weld yma, mae'n rhaid i mi ddefnyddio'r logfail. Bydd hynny'n cael ei chyfathrebu'n leol ar fy nghyfrif. Felly, nid oes angen i mi ddewis hynny i Asim, nid oes angen i mi ddewis hynny i'r cyfathrebu arall. Bydd hynny'n cael ei chyfathrebu'n leol ar fy nghyfrif. Ac yna, yn ddiweddar, pan fyddwn i wedi gwneud hynny, bydd yna rhai pethau y byddwch chi eisiau rhoi i'r logfail hwnnw. Yn y dyfodol, bydd hynny'n gweithle cyfathrebu'n leol ac bydd hynny'n cael ei chyfathrebu'n leol felly byddwch chi ddim yn gallu ei ddarllen. Mae'n rhaid i chi gwneud hynny yma, ond gallwch ei roi i'r sefydliadau gwahanol cyn i ni'w rhoi i'r debyg a gwneud ei ddarllen ar y machin, os ydych chi'n ei ddefnyddio ar gyfer ymchwil. Gallwch hefyd ddewis lle mae'r logfail hwnnw'n cael ei ddarllen. Felly, eto, os ydych chi'n ymchwilio, gallwch ei roi i'r dystod, os na, yn y dyfodol, mae'n mynd i'r ffoldr VAR. Perffaith. Nawr, nawr nad wyf wedi dweud i chi i gyd sut i wneud hynny, ond yr hyn rydw i ddim eisiau i chi ei wneud, nid ydych chi'n ei ddefnyddio ar gyfer y flwydd, os na, mewn gwirionedd. y byddwn i'n gwneud hynny. Oherwydd, eto, rwy'n gwybod pa sy'n mynd i ddigwydd, rydych chi i gyd yn mynd i wneud hynny, yn ei ddefnyddio ar gyfer eich holl flwydd, ac yna, bydd y cefnogaeth yn dod i mi. Rydych chi i gyd yn mynd i ddweud, ie, mae'r hyn rydw i wedi'i wneud heddiw, yw o'r llogfa leol honno. Felly, mae'r holl enghreifftiau rydw i wedi'u ddangos i chi o'r llogfa hwnnw hefyd. Felly, rydyn ni ddim yn gwneud unrhyw beth nad ydych chi'n gallu ei wneud, ond dwi'n gobeithio nad ydych chi'n ei ddefnyddio ar gyfer y flwydd honno. Iawn. Nid ydw i'n gallu hyfforddi hynny llawn, oherwydd bydd y cefnogaeth yn dod i mi. Nid yw'r lle ffynedig i fod. Iawn, bydd Thomas yn mynd i'w ddod i ni drwy rai scenarioau o ran sut y gallwn ddefnyddio telemetru i ystyried pethau sylfaenol. Iawn, diolch, Scott. byddai'n ddifrifol heddiw, os nad ydych chi'n siarad am AI. Felly, mae gennym ddefnyddio bywyd real. Yn gyntaf, dwi'n mynd i ddechrau i fynd â chyfathrebu ar y rhain o statwsiadau. Efallai y gwelwch un o'r statwsiadau ar y tŷ yma'r blynyddoedd, yma'r cyfnod. Felly, 98% o sefydliadau adnabod defnyddio bywyd real ar eu pennau. Felly, mae llawer o bobl sy'n rhedeg Cloud Code, Copilot, ChatGPT, Perplexity, ac ati. Felly, mae angen argymhellu polisi a bywyd real. Iawn, OK, felly, iawn, rydyn ni'n defnyddio, Iawn, yn syniadol, ar gyfer y dyluniau AI, rydyn ni'n cael nifer o ffyrdd gwahanol y gallwch wneud hynny. Gallwch edrych ar diwydiantau'r broses, edrych ar diwydiantau'r spond, os oes un dylun sy'n benodol neu un dylun sy'n benodol neu un sy'n benodol neu un sy'n benodol neu un sy'n benodol Felly, mae nifer o ffyrdd gwahanol y gallwch wneud hynny i ddysgu'r dylun hwn hefyd. ond mae'r rhain yma rydyn ni'n mynd i siarad am hyn a nifer o ffyrdd mwy hefyd. Felly, mae gen i'r Mac i mewn yma ac eto, rydyn ni ddim yn gwneud rhywbeth cymhawn yma, ni ddim wir yn siarad am y broses gynnydd yma. Rydyn ni'n fwy siarad am y dylun rydyn ni eisiau ddylun Yr un o'r rhai yma sydd wedi cyhoeddi chatGPT yn eu sefydliad? Ychydig o bobl, iawn. Clodd? CoPilot? Ie, mae pawb yn mynd i fyny yno, Ie, dyna'r hyn. Felly, gallwch weld nawr bod y ffail wedi'i gysylltu ac eto, rydyn ni'n mynd i ddynnu hynny i ddysgu'r dylun a'i sefydlu. Ond rwy'n meddwl bod llawer o ddefnyddwyr yn dweud Rydyn ni'n mynd i ddynnu hynny a'i sefydlu. Felly, mae'r defnyddwyr yn dweud un ffordd, ond mewn gwirionedd, mae'r Mac yn dweud llawer mwy i hynny. Yn ôl, gallwch weld yma fod o'r hyn mae'r dylun a'r ffail o'r canción Fe'i ffinio, ac maent yn dweud na maen nhw'n bwysio y gwirionedd. Allwch weld ein bod ni'n ffinogen at HOY trendy ac yna yiminyg gyda'r desert-dweud Yna gallwn weld y defnydd o'r gwasanaeth hwnnw. Gallwn weld bod com.openai.chat yw'r syniad o hynny a gallwn weld ei fod wedi'i lansio ei hun a gallwn weld y defnydd sydd wedi'i wneud hynny hefyd. mae hyn yn ddefnyddiol iawn nid dim ond i'r cyfrifiadau ond, eto, os ydych chi'n gwneud'r ffenog sy'n ymwneud â hyn fel, a oedd y defnydd wedi'i lansio, a oedd rhywbeth eraill wedi'i lansio neu, a yw'n dim ond mae'r ffenog sy'n ymwneud â hyn yn cael ei ddweud hynny ond mae'r syniad sy'n ymwneud â hyn yn rhywbeth gwahanol hefyd. Fel, mae'r holl ffenog gwahanol hyn rydyn ni'n edrych arnyn nhw ar ein amgylchedd. Ac yna, yn ddiweddar, eto, rwy'n gallu gweld yng nghanol, roedd hyn yn ddiddorol oherwydd dydw i ddim yn gwybod felly roeddwn i'n edrych trwy'r ffenog hwn fy hun. Mae ChatGPT yn gadael gwasanaeth gweithredu gwahanol a dydw i ddim yn gwybod amdano. Mae'r ffenog hwn yn cael ei gadael'n ymddygiadol. Felly, pan fyddwch chi'n ei lansio, byddai'r ffenog hwn yn ei gadael yno. Ac eto, rydyn ni'n gallu cael y math o ddata hynny hefyd. Felly, a yw pethau'n cael eu gadael i'ch amgylchedd rydych chi ddim yn gwybod amdano trwy'r ffenog hwn? Felly, efallai os ydych chi'n gadael ChatGPT, ydych chi'n gwybod popeth eich Mac i'w lansio? Ac nid, yn amlwg, mae'n cael ei gadael yn fwy ac yn fwy o lefel cyhoeddus ac yn fwy bwysig wrth i'r math o aelodau eraill ddod allan, fel Clod, CoWork a Codex a pheth. Felly, mae'n ddefnyddiol iawn o'r pwynt yma. Ac eto, mae'n hollol dda oherwydd rwy'n gallu gweld bod hwn wedi'i lansio gan y com.openai.chat hefyd. Felly, mae'r syniad sylfaenol yn dal i fod yn yr un peth, felly rwy'n mynd i ddiolch iddyn nhw, Perffaith. Felly, Thomas, allwn ni wneud mwy? Ie, mae'n deimlo llawer, fel llawer o ddata, llawer o wybodaeth, llawer o gwybodaeth ddiddorol sy'n cael o'r telemetru. Felly ie, yw yna rhywbeth mwy? A'r cyfrifiad, ie, gallwn rhoi mwy. Felly, mae'r broses yn rhoi i chi un ffyrdd, mae'r cyfrifiad, rydych chi'n meddwl beth mae'n cael ei hysbysu, a byddwn ni'n mynd i'w ddarparu a byddwn ni'n byddai'n ar gyfer gyhoeddiad genedlaethol. Roedd yn beta, efallai nad ydych chi wedi sylfaenoli. Felly, ie, ar ôl testu a chysylltu'r adroddiad, byddwn ni'n mynd i amrywion fel mae cyfleoedd y debyg sy'n mynd yno, ond rydyn ni hefyd yn edrych ar y rhan o'r rhain o'r gweithredu. Felly, a yw un o'r rhai yma sy'n cael llawysgrifau'n rheoli neu llawysgrifau'r debyg ar eu debyg? Iawn, mae llawer o bobl. Iawn, iawn. Pa ffordd y gwnaethoch chi gweithredu bod hynny'n gweithio? Nid oes unrhyw beth. Rydych chi'n mynd ymlaen, iawn, oherwydd rydych chi'n cael y gofyn. Iawn, iawn. Iawn, iawn. Felly, dyma beth y gallwn ei wneud gyda'r telemetru'r diwedd, y gallwn ddechrau ymweld â hynny. Felly, mae profil gwahanol y gallwch ei rhoi i mewn i ymweld â'r diwedd. Felly, eto, nid wyf yn mynd i ysgrifennu i ChatGPT. Dw i'n mynd i lansio'i gweithredu. Dw i'n mynd i ddod i mewn i'r ffenestr hwnnw, ond dwi ddim yn mynd i ysgrifennu. Felly, dw i'n mynd i'w gosod fel hyn. Ac eto, mae'r brosesau gwahanol sy'n mynd ymlaen yma. Ac eto, mae hyn yn rhywbeth sy'n ei wneud ein defnyddwyr bob dydd, ac nid dim ond gyda'r dyluniau sy'n mynd a'u gweld eu hunain, ond gyda'r dyluniau rydych chi'n eu rhoi hefyd. Fel eto, dyluniau cyhoeddu. Ac eto, os edrychwn ymlaen nawr, gallwn weld bod dynion newydd ymweld â network connect. Ac rwy'n gallu gweld bod y broses hwnnw wedi'i ddod allan. Felly, mae gennym ddod allan a ddod allan telemetru network yno hefyd. Felly, yn ddefnyddiol iawn. Ac eto, nid ydyn ni'n gwneud unrhyw beth i blocio hyn yma. Rydyn ni'n defnyddio'r holl beth i'w gweld. Ac yma, mae gennym nifer o ddata gwahanol. Felly, gallwn weld y deunydd lleol, ac yna gallwn weld y pwynt cyhoeddus sy'n mynd i mewn hefyd. Felly, gallwn weithredu lle mae'r traffig yn mynd i mewn. Gallwn gysylltu ddata gwahanol fel dynion IPv rydyn ni'n mynd i'w ddefnyddio, ac efallai pwyntau sydd eisiau eu cyrraedd hefyd. Gallwn hefyd ddod â'r brotocol socket hefyd. Ac eto, mae hynny'n un o'r binariau lle mae'r niferau yn ymwneud â pethau. Felly, nid ydyn ni'n mynd i'w ddysgu heddiw, oherwydd byddwch chi'n gwblhau'n hyn cyn i chi fynd i'r ystafell. Ond mae'r holl beth hwn wedi'i ddatblygu mewn model ddata. Ond gallwch weld yma, beth sy'n ddiddorol am hyn yw bod hyn yn y llwybr cyhoeddus sy'r defnyddwyd y defnyddwyr. Felly, ar ôl eu bod nhw'n mynd i'r wefan, rydyn ni'n dechrau cyllid y data am sut maen nhw'n dod yno'n gyntaf hefyd. Felly, ar ôl hynny, mae'r consent.google.com. Felly, nid ydyn ni'n edrych ar rai o'r pethau rydyn ni'n eisiau, ond rydyn ni'n cyllid yr holl data cyn i'r defnyddwyr dod yno. Felly, fel sydd wedi siarad amdano, nid ydyn ni'n edrych ar y broblem, rydyn ni'n edrych ar y cyn a'r diwedd hefyd. Felly, os ydych chi'n cael ei ddod i'r broblemau neu'n ymweld â'r broblemau, byddwch chi'n gallu gweld yr holl hynny yma. Ac, eto, mae mwy o ddata i'r telemetra'r rhain hefyd. Felly, mae ffail fawr, dim ond i'r consent.google.com. Rydyn ni'n dechrau gweld, eto, rydw i wedi cael cysylltiad arall. Ac, eto, dyma'r holl fath o ddod i'r brosiect yn mynd i hynny. Ac erbyn hyn, rydw i'n dechrau gweld bod dyma lle maen nhw wedi mynd i chat.gpt.com. Felly, maen nhw wedi clicio drwy'r llin. Ac, eto, rydw i'n cael yr un fath o ddata. Rydw i'n cael'r port. Rydw i'n cael'r fersiwn IPV hefyd. Ac rydw i'n cael'r host o'r pwynt cyffredin cyffredin yn ogystal â'r host lleol, sy'n gallu i mi wneud hynny'n gwirionedd. Roeddwn i'n blaenio'r adroddiad IP'r host lleol er enghraifft, oherwydd roeddwn i'n gwybod beth yw'r adroddiad sydd wedi'i lansio. A oedd yn safari? A oedd yn browser gwefan arall? Rydw i'n cael'r broblem honno. Rydw i'n cael'r holl hynny yn y ffail honno hefyd. Ac yna, yn ddiweddar, rydw i'n cael y cysylltiad hwnnw hefyd. Rydw i'n dechrau gweld pa rydyn ni'n mynd ymlaen yma. Ond gallwch weld yma bod hynny mewn gwirionedd o'r gwasanaeth chat.gpt hefyd. Ar ôl hynny, gallwch weld ei fod wedi'i lansio o'r ffolder, y ffolder gwasanaethau. Felly rydw i'n dechrau gweld hynny. Ac os ydw i'n mynd allan, rydw i'n dechrau gweld nad yw'r enw hyfforddus hwn yn rhywbeth rydw i'n ei gobeithio fel rhan o'r gwasanaeth OpenAI. Felly, unwaith eto, dim ond clicio'r defnyddwr a'i lansio, gallwch weld y gwahanol fforddau o telematri gwasanaeth gweddill sy'n ei ddangos. Felly, os yw'r tŷ hyfforddus hwn, efallai y byddwch chi'n gwblhau'r tŷ hyfforddus ond efallai y byddwch chi hefyd yn rhaid ei alluogi hefyd. Felly, gallai'n ddefnyddiol iawn i'r broses gwasanaeth hyfforddus honno, fel, eto, mae'r gwasanaeth newydd yn cael ei ddatblygu neu, efallai, mae'n ffrindiau da ar Apple yn hoffi newid yr URL-au ac efallai nad ydynt bob amser yn newid y datblygiad yn gyflym, gallwn gael rhai o'r mathau o fathau hyfforddus yno hefyd. Ond gallwch weld, eto, nid oes unrhyw beth anodd yn digwydd, ond nid yw'r enw hyfforddus ymlaen rydw i'n gobeithio ar y broses gwasanaeth hyfforddus honno. Felly, eto, dim ond rhywbeth yn ddiddorol iawn i'w weld. Ac yna gyda hynny, mae gen i llawer mwy o ddata hefyd sy'n gallu i mi ddod o hynny. Ac yna yn ddiweddaraf, eto, rydw i wedi clicio'r llys yma, felly, eto, rydw i wedi cael y broses gwasanaeth hyfforddus honno a'r llwybrau lleol. yn yr off openai.com. Felly, eto, mae'n ddefnyddiol i weld fy mod i'n gwybod pan mae'r defnyddiwr eisiau mynd, ond eto, rydw i'n gobeithio ei weld yn y cyntaf cyn i mi weld yr un cyntaf, ond eto, mae'n mynd i ddangos sut mae rhai o'r appau hyn o'ch ddefnydd. Felly, mae'n mynd i'w ddangos oherwydd mae'n ddangos Felly, eto, mae'n ddiddorol iawn i weld pan oedd yn chat.gpt oherwydd mae'n mynd i'w ddangos i'r ffordd y byddwn i'n ei ddangos fel safari yma fel rhan o'r brosesau. Felly, gallwch weld yna gyda telematri'r rhain. Rydyn ni'n adeiladu'r ffordd hynny hefyd. Rydyn ni'n mynd â nhw drwy'r ffordd hynny. Rydyn ni'n gallu gweld bod yn dechrau gyda search Google. Yna, maen nhw'n dod i'r destinatiaid y maen nhw eisiau, a oedd chat.gpt.com. Ac yn ddiweddar, rydw i hefyd yn cael y cyfathrebu'r app honno. Ac mae hynny'n un o'r profil rydyn ni wedi'i asgrifio ar y machin honno. Felly, eto, mae'n cael cael cyflwyno'r holl ddata telematraidd ar gyfer ni. Felly, Thomas, sut allai hynny helpu gynhyrchu ein cyfathrebu'n gyffredinol? Ie, yn unig, diolch. Rydyn ni wedi cyflwyno llawer, fel sut i gyfathrebu'r cyfathrebu, to collect the signal, which signal to track and work with. cyfathrebu'r cyfathrebu, And yeah, to close the loop, we want to create some policies that will decide either we want to block something, or we have something under review, or we allow it. So yeah, with all this information, we can decide for these policies and set them up to continuously prevent the users from accessing information and so on. Yeah, so again, what we're doing here is we're not just collecting, again, one piece of information. We're collecting it all from a device. And again, you can choose those categories. Again, is it the applications you want to monitor? Is it users? Is it potentially terminal commands? Is it the networks? Is it scripts, binaries? Whatever it is that you want to monitor, we can do that in real time with telemetry to enhance your security policies that you have internally. Obviously, today, I focused on AI, because if you don't include AI, your presentation isn't valuable. So I spoke about AI, but I imagine a lot of people have issues around web browsers as well, around managed web browsers, non-approved web browsers, feels like the next big thing that's exploding. You can absolutely do that as well. With telemetry, again, you can monitor for those application installs. And you can then monitor for those network events if you want as well from those web browsers. So you could do that. And then you can use Jamf Pro as an example to remove them. Again, as I say, I love building support workflows with this. Again, I can attest MDM installs. I can see if a user's approved or denied camera access or microphone access or something that they might need. And screen sharing as well, I can monitor for that. It's not only good for support, because again, how many times you say, right, we're going to remote into this. And the user goes, no, I can't see you in it. And you're like, no, no, we're there. Don't worry. Again, you could monitor for those connections with that. But as part of telemetry, as Thomas said earlier, you can also collect crash logs, and you can collect performance metrics as well. So if you're starting to build a DEX journey, I know that's quite a common thing nowadays as well, you can actually get some of that data as part of telemetry. So again, it's not just a threat hunting service telemetry. It can be a support and DEX workflow as well. OK, so some tips, tricks, and gotchas. That could have been a slip of the tongue there. But yeah, so again, as we've already stated, you can collect this in a local log file, but don't deploy it fleet-wide. So that's the top one. But I won't do the animations again. Thomas, there are a few different telemetry versions, aren't there? Yeah, exactly. We have currently already the legacy one, which was based on BSM event capture. Yeah, it's already incompatible with the future macOSes. So yeah, it's a good point for you. I will show an example later how the network telemetry looks like in Jamf Protect, so you know how to redeploy a different one. The current one is the endpoint. So yeah, that's based on the macOS endpoint security API. Yeah, it covers processes, files, and authorization authentication events. It's a category-based configuration, following hash computation. And it provides our streams to SIEM via JSON. The newest one that I announced a few slides earlier, yeah, that's based on the network extension model. It covers the inbound and unbound connections. It's available per app, per user attribution. And yeah, it provides the full macOS compatibility. Yeah, and as I said, it will be available soon. So yeah, look forward to that. OK, this is the example. So if you log into Jamf Protect and you go to telemetry and you see this banner, so yeah, it says this version is duplicated. So yeah, there is a link to follow our steps how to redeploy the endpoint telemetry. Yeah, so if you're looking like this, you're on the old version, which as Thomas said to reiterate, it's going to be depreciated the way we collect that. So if you went in and played with it before, it will probably still look like this. You can delete it if you've deployed it. There is a migration path that you can use as well. But pretty much the key takeaway is if you're like this, you're on the old version and you're missing out some of the nice stuff that we've shown you today as well, because we're not collecting as much with that legacy version. Yeah, exactly. Already, we know that there are many customers on this version. So yeah, there is a clear path, as Scott said. And yeah, don't feel pressured after this presentation to go with the network telemetry. It's optional. OK, yeah, how to fine tune. Yeah, as we've seen, telemetry can be extremely noisy. And what we do have is we have a process called exceptions. And with exceptions, what you can actually do is tell us not to monitor for that specific process or application or just collect that data. So if you want, you can log in. And these are kind of hidden. But if you look for exception sets, you can actually add in specific team IDs, process, applications, users, even if you want to, like specific users you don't want to collect data for. So if it is that you are finding that telemetry can be quite noisy for a specific process or it's approved, you can actually build an exception. What's nice about exceptions as well is you can actually build multiple different groups and scope them to different users. So as an example, if you want to, you probably want to monitor for everything on an exec's laptop maybe. So you don't want to build an exception set. But maybe for HR and they're always in workday, you might want to build an exception set for workday, as an example. You can do those types of things with that. So as an example, once I'd installed ChatGPT, I went and got the team ID for it. And I just blocked anything that was signed with OpenAI's signing ID, team ID. And that then stopped me collecting all that data around it. So the file got a little reduced, but it was still quite hefty once I'd done that as well and started logging with it. Now, what I would say is that there's good exceptions and there's bad exceptions. So be careful what you're doing with that as well. Again, if you then start to block something like Safari, you're going to miss all that network traffic as well. So you kind of do have to think about what it is that you want to block. Because what you think might be good could end up resulting in a bad thing and you miss a lot of detail as well. So just work around that. And we also, as part of Protect, build by default in a set of exceptions anyway. So we don't monitor specific files or processes or folders. So by default, we've already got certain things turned off. So if there is something that you think, oh, it isn't collecting this, it's worth just checking the default exceptions that you're pushing down to the machine as well, because that might have some of those processes and events in it. And again, there you go. That's what they'll look like. So again, you can see there, we don't collect things from library application support or VAR install and such. So if that is a folder that matters to you and you feel like it's not being collected, it will probably be because it's in the default exception set. So you can go in and actually edit this as well and change it. You can also clone it as well if you want and actually add on top of it. So if you want to add a bit more, you can take that and clone and add on top of it as well. Perfect. So I know I've been telling you, oh, AI is scary and all this. But it's quite useful when it comes to reading that log file as well. So obviously, we've got a tool internally that can read that log file, hopefully coming later this year for testing. But what you can also do is you can take that log file, and again, it's just a JSON file, and you can actually give it to AI. And within three minutes, Claude had built this for me, took that whole log file, that 9,000 events, and actually then started to build this. So within this, I then had this. I was able to share it with the rest of our team. And even we didn't know some of the stuff that was going on. And this was just a test Mac. So again, you can start to see some of the event types that you get, some of the processes, the active users. And again, this was all generated in a matter of an hour, all these different types of things. So there's a fair number of events going on in the background of your Mac that you might not be aware of. Again, I get the top processes. I can even see the top network destinations, because again, I've put on that network telemetry there. So again, really useful from that point of view if you don't know, again, what your users are reaching out to. No idea why WeatherKit is so high in that list as well. I don't think I checked the weather once, but there you go. Shows how much it's talking in the background to Apple to get that. And then again, we've also got some of that real nice analytics stuff that we've got built into Protect. You can start to see that, and it's linked to the MITRE framework. So that could even be built into your telemetry log file if you want as well. And I can see that the application network traffic from some applications there as well, specifically around chat GPT. Another one, pseudo events. So again, collecting anything that's done in terminal. Again, I can see defaults is used quite a lot. I didn't type defaults once into my Mac. So again, this is all these applications we've got running in the background doing that. Again, monitoring and collecting that type of events. And a few RMs in there as well. So again, what are people deleting off their machine? We can collect all that type of data. Now, obviously, we've used AI as an example of what you can monitor. Again, I think web browsers is another one. If AI is something that you want to start to monitor and manage, you obviously seen it in the main keynote this morning. But we do have a webinar coming up around that as well. So if you can't scan a QR code, you can also just go to jamf.it.gnl.ai. There are multiple different dates on there or different times that you can sign up to. I think it's happening next week, 25th of June. So yeah. Correct. Yeah. Everyone got a picture of that who needs it? I still see a few phones in the air. But yeah, if not, jamf.it.gnl-ai. You'll be able to get to that. So what can we take away from this today then, Thomas? Yeah, we wanted to show you that telemetry is really powerful and can provide you already with some more visibility. You can build upon it with network telemetry. The suggestion is to start today. Do not hesitate. Do not delay it anymore. And start small piece. So yeah, do not deploy feed wide. And yeah, do step-by-step, some testing, and so on. And try to work with the data and get some understanding. And yeah, the last takeaway is AI is also a friend. Similarly, a SIM is your friend. So yeah, don't be afraid to use AI. OK, yeah, and with that, we can open the floor to questions. There is also one more QR code. In the meanwhile, there we cover the slides. There will be also the recording of the presentation. There is a migration documentation There will be more documentation on the network telemetry once released. Perfect. Thank you, Scott and Thomas, for that one. Round of applause, everyone, for Scott and Thomas. So we do have two or three minutes for any questions. Has anyone got one or two questions they may want to ask or?

TL;DR

  • Apple endpoint telemetry in Jamf Protect is built on Apple's native Endpoint Security Framework and ESLogger — Jamf serializes and forwards the JSON output rather than running its own agent on the device.
  • Telemetry closes the visibility gap that blocking alone cannot fill, capturing events like privilege escalation, file deletions, MDM profile changes, screen sharing sessions, and network connections in real time.
  • Monitoring unsanctioned AI tools like ChatGPT is a primary use case: process events and signing IDs reveal background services and outbound connections that users and admins are typically unaware of.
  • Exception sets allow fine-grained noise reduction by suppressing collection for specific processes, team IDs, users, or folders — but poorly scoped exceptions can cause critical data like browser network traffic to be missed.
  • AI tools like Claude can parse thousands of telemetry events and generate actionable dashboards in under an hour, making telemetry accessible even without deep SIEM expertise.

What Apple Telemetry Is and How It Works

Presented at Jamf Nation Live London 2026, this session by Tomáš Nespěchal and Scott Mackay delivers a practical, hands-on introduction to Apple endpoint telemetry using Jamf Protect. The speakers begin by distinguishing telemetry from blocking: security tools can prevent threats, but telemetry closes the visibility gap by surfacing everything that happens on a device — logins, USB insertions, privilege escalations, network connections, file deletions, and more. Technically, telemetry is not a Jamf invention but is built directly into Apple's operating system via the Endpoint Security Framework. Jamf Protect monitors ESLogger, serializes the resulting JSON output, and forwards structured, readable event data to a SIEM or other endpoint. The JSON telemetry structure is organized around events — top-level categories analogous to genres — with specific event types nested beneath them. Particularly useful event types highlighted include screen sharing session attach and detach, MDM profile installation and removal, and TCC permission modifications, all of which have direct security and compliance value.

Monitoring AI Tools and Managing Telemetry Noise

A central use case explored in the session is monitoring unsanctioned or ungoverned AI applications. The presenters demonstrate that when ChatGPT is installed and launched, it silently registers background services and makes outbound network connections that users are unaware of — all of which are captured through process events and signing IDs such as com.openai.chat. Network telemetry extends this visibility to inbound and outbound connections, allowing administrators to follow the full network path of any application. The session also addresses the practical challenge of telemetry noise and SIEM cost. Jamf Protect supports exception sets that allow administrators to suppress data collection for specific processes, team IDs, applications, users, or folders. Default exceptions are built in — for example, library application support and VAR install directories are excluded by default — and administrators can clone and extend these sets to match their environment's needs.

Setup, AI-Assisted Analysis, and Key Takeaways

The session covers three primary setup options for telemetry output: forwarding to a SIEM endpoint, storing to S3 cold storage, or writing to a local log file for testing. The presenters strongly advise starting with a local log file on a single test machine rather than deploying fleet-wide, emphasizing an incremental, step-by-step approach. A notable demonstration shows how Claude, an AI assistant, was used to parse a 9,000-event telemetry log file and generate a structured dashboard — including top processes, active users, network destinations, and MITRE framework-linked analytics — in under an hour. This positions AI as a practical tool for making raw telemetry data actionable without requiring deep SIEM expertise. The session closes with a call to action: start using telemetry today, build incrementally, and use both SIEM and AI tools to extract value from the signal. An upcoming Jamf AI governance webinar is also promoted for organizations looking to formalize AI monitoring policies.

Chapters

0:00 - Introduction and Audience Poll
1:47 - What Telemetry Is and Isn't
3:18 - Endpoint Security Framework and ESLogger
4:30 - Telemetry JSON Structure and Event Types
6:23 - Useful Event Types: Screen Sharing and MDM
13:21 - Setup Options: SIEM, S3, and Local Log
17:54 - Monitoring Unsanctioned AI Tools
23:01 - Network Telemetry and App Connections
33:56 - Fine-Tuning With Exception Sets
36:27 - Using AI to Analyze Telemetry Logs
38:17 - Key Takeaways and AI Governance Webinar

Key Quotes

3:03 "Blocking these things isn't the same thing as having the visibility. And that's the gap that telemetry is closing."
3:30 "It's not actually something that we've built. It's actually built into the operating system itself."
4:10 "We, at Jamf Protect, serialize that JSON and make it a little bit prettier and easier to read for you to put into another tool."
35:19 "What I would say is that there's good exceptions and there's bad exceptions. So be careful what you're doing with that as well."
36:45 "Within three minutes, Claude had built this for me, took that whole log file, that 9,000 events, and actually then started to build this."
39:13 "The suggestion is to start today. Do not hesitate. Do not delay it anymore. And start small piece."

FAQ

Does Jamf Protect install its own agent to collect telemetry, or does it use something built into macOS?

Jamf Protect does not run its own collection agent. It monitors ESLogger, a tool built into macOS via Apple's Endpoint Security Framework, and then serializes and formats the resulting JSON data before forwarding it to your chosen endpoint such as a SIEM or S3 bucket.

How should organizations start with Apple telemetry without overwhelming their SIEM or generating too much noise?

The presenters recommend starting with a local log file on a single test machine rather than deploying fleet-wide. From there, use exception sets to suppress noisy but low-risk processes, and incrementally expand scope as you develop familiarity with the data. AI tools can also help parse large log files quickly during the learning phase.

Can telemetry be used to monitor AI applications like ChatGPT or Claude across a Mac fleet?

Yes. Process events and signing IDs — such as com.openai.chat — allow administrators to track when AI applications are installed, launched, and what background services they register. Network telemetry extends this to outbound connections, revealing what external endpoints these tools communicate with.


Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Management
  • Security Operations
  • AI & Machine Learning
  • Threat Intelligence
  • Technical Deep Dive
  • Demo
  • Best Practices
  • Apple Endpoint Security Framework
  • Jamf Protect telemetry
  • macOS security visibility
  • AI application monitoring
  • SIEM integration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Apple Endpoint Telemetry with Jamf Protect

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version