Posted on 11-01-2023 12:13 PM
Hello Jamf Protect Community,
I received an alert with the Description: JamfProBinaryModified.... Jamf Pro Binary Modified or Removed. Below I will copy information from the first two pages of the of the alert. Has anyone encountered this before and if so what resolution did you come to with it? It seems to be related to the appstore but I'm not sure why exactly this is happening and why Jamf Protect isn't simply marking this as Informational if that's what it is.
----
Summary Page:
The Jamf binary is responsible for most of the actions taken by Jamf Pro. It is located at /usr/local/jamf/bin/jamf (alias at /usr/local/bin/jamf). If this file (or its alias) is moved or damaged, Jamf Pro will be unable to perform remote management actions. While an attacker might theoretically disable Jamf Pro to subvert its security controls, this detection is aimed at the end user disabling Jamf Pro without authorization. This detection alerts when the Jamf Pro binary itself has been removed or tampered with.
Remediation:Pay particular attention to the initiating process. In the event that the command “jamf removeFramework” was executed under a terminal, the Jamf Pro binary was likely removed intentionally by the end user. Determine whether this action was authorized by your organization. |
Host IP
Tags
Event Type
Event Timestamp
Path
Process
User
Group
Process Arguments
Signing Info
Path
Process UUID
Pid
Name
User
Group
Process Start Time
Parent Process
Process Arguments
Signing Info
Path
Process UUID
Pid
Name
User
Group
Process Start Time
Parent Process
Process Arguments
Signing Info
Path
Process UUID
Pid
Name
User
Group
Process Start Time
Solved! Go to Solution.
Posted on 11-08-2023 09:53 AM
Posted on 11-08-2023 09:53 AM