Anybody care to share their experiences with application WhiteListing tools? I've been asked to investigate what's available in that arena, and two tools that were specifically mentioned are Google's open source Santa project, and Avecto's Defendpoint for Mac.
Santa seems to be a non-starter as you have to compile a kext, and Apple has all but explicitly said that organizations are not going to get a kext signing certificate for internal use.
Defendpoint for Mac has been mentioned on Jamf Nation before, but my take on those comments is that it's not yet a mature product (and with the usual potential of the kext breaking every time Apple issues an OS update).
Thanks.
