Sign in

Pete Markowsky

@plm.bsky.social
218 followers 195 following 89 posts

Cofounder & CEO @northpolesec.bsky.social Prev: @google working on Security Agents including Santa. Cofounder and Chief Architect @capsule8 (tweets are my own.) Personal Blog: blog.markowsky.us Company Website: northpole.security

PostsRepliesMedia
Pete Markowsky @plm.bsky.social · 10/07/2026
This version always has me thinking of the opening of Blade youtu.be/gHBhKbF2xMA?...
youtu.be
Blade (1998) - Opening Scene (HD)
YouTube video by Yoda
110
Pete Markowsky @plm.bsky.social · 21/05/2026
Lots of the hardening in this release came from us proactively auditing Santa w/LLMs If you're responsible for any OSS, I highly recommend doing the same. You want to be the one finding the bugs first Very happy we invested heavily in design, least privilege & invariants
000
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 13/05/2026
Happy to report we got our SOC 2 Type II in April of 2026. We've been so busy getting the next versions of Santa and Workshop together we forgot to share the good news.
001
Pete Markowsky @plm.bsky.social · 30/04/2026
This set is great www.youtube.com/watch?v=gfF8...
youtube.com
Fred again.. & Thomas Bangalter (USB002, Alexandra Palace, London 27 February 2026)
YouTube video by Fred again . .
010
Pete Markowsky @plm.bsky.social · 24/12/2025
CEL has a lot of features and is often a good way to remove unneeded functionality e.g. preventing users to run Electron apps with --inspect or Chrome with remote debugging. You can also block env vars so if you need to stop the DYLD_ env vars you can. More CEL functionality to come.
000
Pete Markowsky @plm.bsky.social · 23/12/2025
A fun little entry where we can use network extension entitlements to flag remote access tools and VPNs. macOS entitlements are kinda slept on for detection & prevention It's not a silver bullet, but it certainly gets you a lot of coverage without maintaining a list.
010
Pete Markowsky @plm.bsky.social · 22/12/2025
Other fun things we posted over the weekend @northpolesec.bsky.social - Day 21: macOS insecurity - blocking dump-keychain northpole.security/blog/2025-ad... - Day 20: Where's the remote - blocking users from enabling SSH & remote apple events via systemsetup northpole.security/blog/2025-ad...
000
Pete Markowsky @plm.bsky.social · 22/12/2025
This is another old one & a classic from @theevilbit.bsky.social's Beyond Good Ol' LaunchAgents theevilbit.github.io/beyond/beyon... Workshop and Santa's File access rules were built to allow you to lock down directories like this to just the apps that need it & quickly get legitimate approvals.
000
Pete Markowsky @plm.bsky.social · 12/12/2025
This is probably the most common, known & least stealthy option for malware to persist This year Kristin Smith gave a solid talk at BSides Canberra on using models & our file access rules to find anomalous creation LaunchDaemons You can see the talk here youtube.com/watch?v=YJWf...
youtube.com
Is this binary Naughty or Nice? How Google leverages ML and Santa to detect persistence on MacOS
YouTube video by BSides Canberra
010
Pete Markowsky @plm.bsky.social · 11/12/2025
This is an oldie but can still be relevant. @theevilbit.bsky.social calls it out directly in his blog series Beyond Good Ol' LaunchAgents theevilbit.github.io/beyond/beyon...
theevilbit.github.io
Beyond the good ol' LaunchAgents - 5 - Pluggable Authentication Modules (PAM)
This is part 5 in the series of “Beyond the good ol’ LaunchAgents”, where I try to collect various persistence techniques for macOS. For more background check the introduction. PAM originated from Red...
000
Pete Markowsky @plm.bsky.social · 10/12/2025
This is a super common technique for infostealers e.g. Huntress blogged about this yesterday www.huntress.com/blog/amos-st... just blogged about AMOS doing this yesterday, after tricking users to install their malware via AI generated instructions to use bash and curl.
000
Pete Markowsky @plm.bsky.social · 10/12/2025
Always enjoy your set lists. Thanks
110
Pete Markowsky @plm.bsky.social · 08/12/2025
One thing I like about our system is that it's easy to make these kinda trip wires where you can lock these things down. But quickly make an exception if you need to allow something and then dial it back off.
000
Pete Markowsky @plm.bsky.social · 08/12/2025
media.tenor.com
a baseball game is being played with movieclips.com written on the bottom of the screen
ALT: a baseball game is being played with movieclips.com written on the bottom of the screen
000
Pete Markowsky @plm.bsky.social · 07/12/2025
This is another simple but powerful control. You almost never need to disable Gatekeeper. And if you do you should be able to handle that on a case by case basis.
000
Pete Markowsky @plm.bsky.social · 06/12/2025
Stopping things like infostealers by locking down the cookie jar to just the signed browser processes is a simple but powerful control While Chrome is working on Device Bound Session Credentials (DBSC). You can deploy this today. Also if you use another browser like Firefox, it'll still work.
011
Pete Markowsky @plm.bsky.social · 01/12/2025
This is a great feature that I'm using daily. Honestly feels like we found a solid way to close the monitor mode is always on for devs gap. Super proud of the team @northpolesec.bsky.social for landing this
020
Pete Markowsky @plm.bsky.social · 24/10/2025
What about the imaginary CISO?
030
Pete Markowsky @plm.bsky.social · 11/10/2025
Will be curious to get your thoughts on it. The soundtrack is great. But something feels off about it for me.
120
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 09/10/2025
Join us in celebrating North Pole Security's first anniversary! 🎉 Reflect on a year of innovation, growth, & unwavering commitment to livable security with Santa and Workshop. Read about our journey and what's next! #FirstAnniversary #Santa #Workshop northpole.security/blog/one-yea...
001
Pete Markowsky @plm.bsky.social · 30/08/2025
media.tenor.com
a man in a suit says " don 't you think she looks tired " to another man in a suit
ALT: a man in a suit says " don 't you think she looks tired " to another man in a suit
020
Pete Markowsky @plm.bsky.social · 03/08/2025
m.media-amazon.com/images/I/71m...
110
Pete Markowsky @plm.bsky.social · 03/08/2025
Headed to hacker summer camp looking first to seeing people and sharing @northpolesec.bsky.social’s Workshop with people.
010
Pete Markowsky @plm.bsky.social · 03/08/2025
Tbh I did it because it seems to get the word out to folks who’ve split from Twitter, to Bluesky and mastodon. LinkedIn seems to be one of the few common spots. Also I’m stuck on the plane.
100
Pete Markowsky @plm.bsky.social · 31/07/2025
In case you see me. Yes this is why I look so exhausted. 😂
020
Pete Markowsky @plm.bsky.social · 31/07/2025
It's not just one release, it's two!
120
Pete Markowsky @plm.bsky.social · 30/07/2025
It's been an 11 month journey to build Workshop, the integrated backend Santa always deserved Lots of things we'd always wanted at Google are now real The MVP's already powerful & we're just getting started Thank you to Zane & the team at A16Z, Royal Hansen and the team @northpolesec.bsky.social
020
Pete Markowsky @plm.bsky.social · 29/07/2025
I made this gist gist.github.com/pmarkowsky/9... to show how @northpolesec.bsky.social Santa FAA rules lockdown the Spotlight importers used in Sploitlight microsoft.com/en-us/securi... & @theevilbit.bsky.social's persistence trick. I also added an example rule for blocking access to the DBs.
gist.github.com
Santa FAA rule to prevent spotlight plugins from being registered
Santa FAA rule to prevent spotlight plugins from being registered - sploitlight.md
010
Pete Markowsky @plm.bsky.social · 24/07/2025
Going to be attending @bsideslv.org and around. Summer camp. If you’re around say hello.
110
Pete Markowsky @plm.bsky.social · 08/07/2025
This was a big release. Getting CEL in opens up so many possibilities and like all good things it's a take what you need. Really looking forward to seeing what people do with this.
010
Pete Markowsky @plm.bsky.social · 29/05/2025
Lots of great features in 2025.5. Santa is now easier to use without having to drop to the command line. Be sure to check out the videos in the 🧵
110
Pete Markowsky @plm.bsky.social · 14/05/2025
It’s something that feels like the sci-fi future media promised us as kids
010
Pete Markowsky @plm.bsky.social · 11/05/2025
Yikes. Got any other FRs? Asking for a friend…
000
Pete Markowsky @plm.bsky.social · 08/05/2025
Have to admit it's exciting to see years of work coming together.
000
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 08/05/2025
Very exciting to see Santa called out as a tool that works in the @specterops.io SO-Con talk on Modern macOS Red Teaming Tactics by Lance Cain and @werdhaihai.bsky.social www.youtube.com/watch?v=t_L2...
youtube.com
Modern macOS Red Teaming Tactics | SO-CON 2025
YouTube video by SpecterOps
021
Pete Markowsky @plm.bsky.social · 07/05/2025
I hear it’s straight fire🔥… I’ll see myself out.
020
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 05/05/2025
📢 Last week we released Santa v2025.4 github.com/northpolesec... Along with some big changes 🧵
github.com
Release v2025.4 · northpolesec/santa
Notes If you're migrating from Google Santa, please see the Migration Guide for details on how to upgrade. Santa documentation can be found at northpole.dev. Announcements 📣 Opt-In Stats Collection...
101
Pete Markowsky @plm.bsky.social · 23/04/2025
I keep saying these advances are more like electric power tools than fully autonomous. Still means massive productivity gains and chat is now a first class interface in a way it wasn’t feasible previously
000
Pete Markowsky @plm.bsky.social · 16/04/2025
I’m still kinda angry about the whole matter tbh
000
Pete Markowsky @plm.bsky.social · 09/04/2025
Also re:0-day
media.tenor.com
a man in a suit and tie stands in front of a sign that says the work is mysterious
ALT: a man in a suit and tie stands in front of a sign that says the work is mysterious
100
Pete Markowsky @plm.bsky.social · 09/04/2025
I mean I get the fascination it’s pure tech and a narrative that’s often a combo of how clever someone is versus the defenses in place. On the other hand brute forcing passwords, out of date applications and simple malware are still problems for people. So I’m with you.
100
Pete Markowsky @plm.bsky.social · 02/04/2025
Arm me with harmony
000
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 01/04/2025
Today we released Santa v2025.3 on GitHub github.com/northpolesec.... This release includes a handful of new features.
github.com
Release v2025.3 · northpolesec/santa
Notes If you're migrating from Google Santa, please see the Migration Guide for details on how to upgrade. Santa documentation can be found at northpole.dev. Announcements 📣 Opt-In Stats Collection...
111
Pete Markowsky @plm.bsky.social · 31/03/2025
In order to learn MCP I wrote a quick server on top of @northpolesec.bsky.social's Santa github.com/pmarkowsky/s... it provides readonly functionality and debugging.
github.com
GitHub - pmarkowsky/santa-mcp: A PoC MCP Server for Santa
A PoC MCP Server for Santa. Contribute to pmarkowsky/santa-mcp development by creating an account on GitHub.
000
Pete Markowsky @plm.bsky.social · 29/03/2025
Oh?
010
Pete Markowsky @plm.bsky.social · 26/03/2025
Good thing it has that builtin stack overflow www.geoffchappell.com/notes/securi...
geoffchappell.com
America Online Exploits Bug In Own Software
000
Pete Markowsky @plm.bsky.social · 26/03/2025
Got sent this from a friend and admittedly I'm still chuckling.
000
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 05/03/2025
We agree with CISA and think you should use Santa too www.cisa.gov/sites/defaul...
Snippet of the CISA guide recommending that you use Santa to stop living off the land attacks on macOS
001
Pete Markowsky @plm.bsky.social · 03/03/2025
Today in adventures in open source. We've had one user make a PR to update docs 🎉 And on a call a user said thank you for what you folks are doing in the community. Not gonna lie this is pretty great to be on the receiving end of this.
010
Reposted by Pete Markowsky
North Pole Security @northpolesec.bsky.social · 28/02/2025
📣 We’ve just released Santa v2025.2 on GitHub. github.com/northpolesec... Some highlights include: - Process-centric File Access Authorization rules are now in Beta! This means FAA rules can now target all access from a given process without knowing the files that will be accessed ahead of time.
github.com
Release v2025.2 · northpolesec/santa
Notes If you're migrating from Google Santa, please see the Migration Guide for details on how to upgrade. Santa documentation can be found at northpole.dev. Announcements 📣 Opt-In Stats Collection...
111