Skip to content
← All courses

Expert · Lessons: 5

macOS hardening, setting by setting

Reduce the attack surface of a Mac: secure installation, encryption, services, ports, accounts, updates and built-in defences, with the commands to check each one.

Knowledge Units: OSH, OSC Read the Knowledge Units

FireAI University is independent: it is not affiliated with, endorsed by or designated by the NSA or the NCAE-C program. We use their published Knowledge Units as a curriculum guide.

Start the course

  1. 1 Attack surface and a hardening baseline

    What “attack surface” means on a Mac, and the order of operations that turns a default install into a hardened one.

    8 min
  2. 2 Secure installation, startup security and encryption

    How a Mac protects the boot process and the data on disk, and how to check FileVault, the Secure Enclave and startup security yourself.

    9 min
  3. 3 Accounts, users, groups and privileges

    Why a standard account for daily work beats an administrator account, and what a sound password policy actually requires.

    8 min
  4. 4 Services, sharing and open ports

    Turn off sharing services you do not use, see what is actually listening for connections, and turn on the Application Firewall.

    9 min
  5. 5 Built-in defences and verification

    What System Integrity Protection, Gatekeeper, XProtect and Lockdown Mode actually do, and how to check each one is still on.

    9 min

Free, no account, nothing tracked. Your progress stays in this browser.