This talk is focused on red teaming techniques and tools against MacOS hosts in enterprise environments. Below is the outline of topics that will be discussed:-Intro-Agenda-A Look at MacOS Enterprise Deployments (Common technologies, Remote management, Local admin rights, Misconfigurations)-Phishing techniques (Payload types, Credential harvesting techniques)-Gatekeeper (What is it?, How does it work?, Ways around it/limitations)-Post Exploitation Methods and Examples-Common patterns/detection techniques (Parent-child processes, Command line arguments, Network connections)-Migrating to API Calls (How?, Why This is Harder to Detect, Examples)-Defensive Recommendations (Host-based, Network-based)-Q&A