diff --git a/Bash/HuntressSystemExtensionProfileRestricted.mobileconfig b/Bash/HuntressSystemExtensionProfileRestricted.mobileconfig new file mode 100644 index 0000000..e1a4490 --- /dev/null +++ b/Bash/HuntressSystemExtensionProfileRestricted.mobileconfig @@ -0,0 +1,153 @@ + + + + + PayloadContent + + + FilterDataProviderBundleIdentifier + com.huntress.sysext + FilterDataProviderDesignatedRequirement + identifier "com.huntress.sysext" and anchor apple generic and certificate leaf[subject.OU] = "7W6HQ9J9XA" and certificate 1[field.1.2.840.113635.100.6.2.6] and certificate leaf[field.1.2.840.113635.100.6.1.13] + FilterGrade + firewall + FilterSockets + + FilterType + Plugin + PayloadDisplayName + Web Content Filter + PayloadIdentifier + com.apple.webcontent-filter.CA40CCD3-78D3-45AD-83D4-87B83A27BB5C + PayloadType + com.apple.webcontent-filter + PayloadUUID + 6A41F61C-A9A0-4DA9-A72A-AF57D3ADFF33 + PayloadVersion + 1 + PluginBundleID + com.huntress.app + UserDefinedName + Huntress + + + AllowedTeamIdentifiers + + 7W6HQ9J9XA + + PayloadDisplayName + Huntress System Extension + PayloadIdentifier + com.apple.system-extension-policy.50653D8C-681B-496C-A50E-A33E2F45B03E + PayloadType + com.apple.system-extension-policy + PayloadUUID + 937026A5-86ED-40F7-B6C7-B1F65F4917B6 + PayloadVersion + 1 + NonRemovableSystemExtensions + + 7W6HQ9J9XA + + com.huntress.sysext + + + + + PayloadDisplayName + Huntress PPPC + PayloadIdentifier + com.apple.TCC.configuration-profile-policy.341605DE-C729-4B02-A91F-43D9ECF7D145 + PayloadType + com.apple.TCC.configuration-profile-policy + PayloadUUID + C1FC3CD5-8DF4-495A-8343-376A3E35C647 + PayloadVersion + 1 + Services + + SystemPolicyAllFiles + + + Allowed + + CodeRequirement + identifier "com.huntress.app" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7W6HQ9J9XA" + Comment + Full Disk Access for the Huntress Agent + Identifier + com.huntress.app + IdentifierType + bundleID + StaticCode + + + + Allowed + + CodeRequirement + identifier "com.huntress.sysext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7W6HQ9J9XA" + Comment + Full Disk Access for the Huntress Endpoint Security + Identifier + com.huntress.sysext + IdentifierType + bundleID + StaticCode + + + + SystemPolicySysAdminFiles + + + Allowed + + CodeRequirement + identifier "com.huntress.app" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7W6HQ9J9XA" + Comment + Full Disk Access for the Huntress Agent + Identifier + com.huntress.app + IdentifierType + bundleID + StaticCode + + + + Allowed + + CodeRequirement + identifier "com.huntress.sysext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7W6HQ9J9XA" + Comment + Full Disk Access for the Huntress Endpoint Security + Identifier + com.huntress.sysext + IdentifierType + bundleID + StaticCode + + + + + + + PayloadDescription + Huntress PPPC for FDA and System Extension + PayloadDisplayName + Huntress Agent with System Extension + PayloadIdentifier + com.huntress.app + PayloadOrganization + Huntress + PayloadScope + System + PayloadType + Configuration + PayloadUUID + 15C17CDA-5596-42CA-8AB2-25D3B66CAA61 + PayloadVersion + 1 + TargetDeviceType + 5 + +