🎉 Phorion ranked #1 in independent EDR telemetry evaluations. Learn more
Frequently Asked Questions

macOS EDR questions, answered

Everything you need to know about Phorion, the EDR built exclusively for macOS: how it detects and stops threats, how it's deployed, and what it costs.

About Phorion

What is Phorion?

Phorion is an endpoint detection and response (EDR) platform built exclusively for macOS. Rather than extending a Windows-first product to cover Macs, every one of Phorion’s detection and prevention controls is designed solely to protect macOS endpoints.

A single lightweight agent combines threat detection, proactive protections, incident response and deep endpoint visibility, replacing the patchwork of point solutions many organisations use to secure their Mac fleets.

Phorion is built by a team of macOS security specialists with years of offensive and defensive experience. After repeatedly going undetected by existing macOS tooling during offensive engagements, the founders set out to build a more effective defence. You can read more about the team.

What is macOS EDR?

macOS EDR (endpoint detection and response) is security software that continuously records activity on Mac endpoints, detects malicious behaviour, and gives security teams the tools to investigate and contain threats.

Where traditional antivirus relies on signature matching and hash lookups to recognise known malware, an EDR collects rich telemetry (process execution, file access, network connections and more) and applies behavioural detection logic to spot attacker techniques, including ones that have never been seen before. When something is detected, responders can dig into the telemetry, trace the attack and take action such as killing processes or isolating the device.

A macOS-native EDR like Phorion builds on Apple-specific data sources such as the Endpoint Security Framework, the UnifiedLog and TCC events, which provide the visibility needed to catch threats that target Macs specifically.

Why do Macs need a macOS-specific EDR?

Macs need a macOS-specific EDR because most endpoint security products were designed for Windows and adapted for macOS as an afterthought, leaving detection gaps against the threats that actually target Mac fleets.

Attackers targeting macOS increasingly rely on techniques such as ClickFix-style social engineering, supply chain compromises through developer tools and extensions, and infostealers that harvest credentials and session tokens. Legacy approaches like signature matching and AV scanning frequently miss these, and effective detection depends on macOS-specific telemetry such as TCC permission usage, clipboard activity and extended file attribute changes.

Phorion is built solely for macOS, so its telemetry, detections and protections are shaped around how Macs are actually attacked. See how Phorion approaches threat detection for more detail.

How is Phorion different from cross-platform EDRs?

Phorion is different because it focuses on a single platform, macOS, and collects far deeper macOS telemetry than cross-platform vendors, which translates into detections others cannot offer.

In the EDR Telemetry Project’s first macOS evaluation, released in March 2026, Phorion ranked #1, scoring 35 out of 42.7 points (82%), more than twice the score of the next closest vendor. Phorion collects file access events across the board, every use of a TCC-protected service, and file attribute changes, categories that most other evaluated vendors do not fully support. Read the full breakdown.

Phorion also avoids the agent sprawl common on Macs: detection, prevention, hardening and visibility all come from one agent, with transparent detection logic and raw telemetry you can query directly.

Does Phorion replace my antivirus?

Yes, Phorion can replace a standalone macOS antivirus, because it includes integrated antimalware powered by DoubleYou alongside its behavioural EDR.

DoubleYou is signature-based malware detection and prevention from macOS security pioneers Patrick Wardle and Mikhail Sosonkin. It blocks known, commodity malware before it executes, while Phorion’s behavioural detections and Protections cover the novel and hands-on-keyboard activity that signatures miss. Together they provide defence in depth from a single agent.

Read more about how these layers fit together in Beyond Detection: Proactive Process and File Controls for macOS.

Does Phorion replace Apple's XProtect or Gatekeeper?

No, Phorion does not replace Apple’s built-in protections such as XProtect and Gatekeeper; it complements them with enterprise-grade detection, prevention and visibility.

Apple’s defences are welcome and continue to improve. For example, macOS Tahoe 26.4 added Terminal paste warnings and XProtect-based paste blocking. But they are designed for the general user population, are largely closed, and don’t give security teams centralised telemetry or policy control. Terminal’s paste warning, for instance, doesn’t trigger for developers or users who regularly use Terminal, and XProtect’s paste blocking is limited to domains already on Apple’s blocklist.

Phorion layers configurable controls such as Clipboard Protection, behavioural detections and fleet-wide telemetry on top of what macOS already provides.

Does Phorion replace my MDM?

No, Phorion is not a mobile device management (MDM) platform; it works alongside your existing MDM and is deployed through it.

Your MDM (for example Jamf or Kandji) handles device configuration and management, while Phorion provides detection, prevention, response and security visibility. Phorion supports zero-touch deployment via Jamf, Kandji or any other MDM. See how Phorion is deployed.

Does Phorion have documentation?

Yes. Every customer has access to full product documentation inside their own Phorion instance.

Your team can look up how something works without leaving the console, whether that’s rolling out the agent, configuring Protections or investigating an alert.

Documentation is backed by people, too. Every customer gets hands-on rollout support, follow-the-sun support and a shared Slack channel with the macOS specialists who build Phorion, so if the docs don’t answer a question, the team will.

Evaluating Phorion? Book a demo to see the platform and its documentation first-hand.

Does Phorion have an API?

Yes. Phorion provides a full API, so you can connect the platform to your existing security workflows, tooling and automation.

The API is one of several integration options. Alongside SIEM integration and fully customisable webhooks (see what Phorion integrates with), it lets you build custom integrations wherever an off-the-shelf connector doesn’t fit how your team works.

It also reflects Phorion’s transparent-by-design approach. Raw telemetry and full visibility into detection logic are available in Phorion’s built-in SIEM, so your team always has open access to the data behind every alert. Reach out to discuss your integration requirements.

What tools does Phorion integrate with?

Phorion integrates with any SIEM, SOAR or external tool through built-in SIEM integration, fully customisable webhooks and a full API.

SIEM integration brings Phorion’s macOS data into the SIEM your security team already uses. Customisable webhooks connect Phorion to SOAR platforms and any other tool that accepts them. The Phorion API covers everything else, letting you build custom integrations with your existing workflows.

Phorion also works with the tools around it. It deploys zero-touch through Jamf, Kandji or any other MDM, includes a built-in osquery integration for querying your fleet with SQL, and comes with a hosted SIEM, so teams without their own SIEM can still investigate raw telemetry.

Phorion vs alternatives

Why choose Phorion over a larger EDR vendor?

Phorion is smaller than many EDR vendors, but both we and our enterprise customers see that as a benefit, not a drawback.

Our size keeps us agile. Everyone at Phorion is focused on macOS security research, the threats facing Mac fleets and the features needed to stop them. There are no competing priorities from other operating systems or unrelated product lines.

That focus allows Phorion to adapt significantly faster than larger competitors as the threat landscape changes. Our sole mission is protecting the world of macOS, and our customers benefit from a team that can respond quickly and give them direct access to the specialists building the product.

Threat detection

What threats does Phorion detect on macOS?

Phorion detects the threats that actually target macOS fleets, including infostealers, ClickFix and other social engineering attacks, supply chain compromises through developer packages and IDE extensions, keyloggers and spyware, persistence, and command-and-control or data exfiltration activity.

Detection is behavioural, built on macOS-specific telemetry, and ships with a library of hundreds of detections developed from years of offensive and defensive macOS experience. New rules are added continuously as Phorion’s researchers track emerging threats, and integrated DoubleYou antimalware adds signature-based protection against known malware.

For a real-world example, see how Phorion detected and prevented Paradox Stealer delivered through a malicious Cursor extension.

Does Phorion use Apple's Endpoint Security Framework (ESF)?

Yes, Phorion uses Apple’s Endpoint Security Framework (ESF) for real-time visibility into process execution, file operations and network events, which stream directly into Phorion’s detection engine.

ESF is only one source, though. Phorion also collects UnifiedLog entries (which capture system events ESF misses, such as some persistence and privilege escalation activity), TCC access events, clipboard paste activity and extended attribute changes.

Phorion’s team actively tracks new ESF capabilities as Apple releases them. For example, the team reverse engineered the undocumented socket bind events introduced in macOS 26.4.

How does Phorion stop macOS infostealers?

Phorion stops macOS infostealers with layered defences: file access controls that lock sensitive data to trusted processes, behavioural detections, and DoubleYou antimalware that blocks known stealers before they run.

Infostealers are the dominant macOS threat. Phorion’s file access authorization locks browser cookies, SSH keys, developer secrets and credential stores to the processes that legitimately use them, and its cookie theft protections block non-browser processes from reading sensitive browser paths and terminate offending processes the moment they touch protected locations. Because the control defines legitimate behaviour rather than chasing specific malware, it holds regardless of how the stealer is packaged.

Phorion also collects file access telemetry across the board, so if a stealer touches ~/Library/Keychains or a browser cookie store, the evidence is already there for detection and investigation.

What are ClickFix attacks and how does Phorion block them?

ClickFix (or “pastejacking”) attacks trick users into pasting a malicious command into Terminal, and Phorion blocks them with Clipboard Protection, which inspects pastes into terminal applications in real time.

These lures, often disguised as a required update, a fix for a common problem or a one-line installer, are highly effective because they sidestep Gatekeeper and Notarization and use native, Apple-signed binaries. Phorion’s agent tracks which application placed content on the clipboard, where it’s being pasted, what it contains and how the paste happened, covering keyboard shortcuts, menus and drag-and-drop.

Clipboard Protection offers Audit, Smart and Block modes, optional interactive prompts for users, and fully configurable sources, destinations, heuristics and exclusions. Read the Clipboard Protection launch post for details.

Can Phorion protect against npm supply chain attacks?

Yes, Phorion detects and blocks malicious behaviour from npm packages by tracking each npm lifecycle hook (such as install scripts) and applying tightly-scoped protections to anything those hooks run.

Phorion’s research into npm internals lets the agent tag every process, file, network and DNS event with the lifecycle phase, package and version responsible. During lifecycle hooks, Phorion can block activity such as osascript, pbpaste, open and npm publish (which breaks worm propagation used by campaigns like Shai-Hulud), and deny reads of credential files such as ~/.npmrc, ~/.aws/credentials and ~/.git-credentials, all without disrupting normal development workflows.

Read the full research: Detecting and Preventing npm Supply Chain Attacks with Phorion Protections.

Can I write my own detection rules in Phorion?

Yes, Phorion lets you author your own custom detection rules and tune existing ones to fit your environment.

Phorion’s rule engine lets teams build detections tailored to their environment, crown jewels and threat model. You can also tune rule thresholds, add allowlists and adjust severity through the detection development portal, reducing noise without losing coverage.

Detection logic is fully transparent: there’s no black box. Phorion’s built-in hosted SIEM gives you access to raw telemetry, so you can see exactly what triggered each alert, query events and develop new detections from a single interface. Learn more on the threat detection page.

Does Phorion include threat hunting?

Yes, Phorion includes continuous threat hunting by its own research team as part of the platform.

Phorion’s researchers hunt across anonymised customer telemetry for emerging threats. When they identify new tactics, techniques and procedures (TTPs), new detections ship to all customers automatically. Your own team can also hunt directly using the hosted SIEM and the built-in osquery integration.

Protection & response

What are Phorion Protections?

Phorion Protections are proactive hardening controls, process execution controls and file access authorization, that block malicious activity before it becomes an incident, delivered in the same agent as Phorion’s EDR.

Process execution controls shrink the attack surface by blocking process flows that should never happen on a healthy endpoint (for example, a Word document spawning bash) and by removing binaries such as osascript, curl or python from endpoints that don’t need them. File access authorization locks browser data, SSH keys, developer secrets and credentials to trusted, validly-signed processes.

Read the Protections feature page or the launch post, Beyond Detection.

How do I roll out protections without breaking user workflows?

You roll out Phorion Protections safely by using historical EDR analytics to see what a control would have blocked before you enforce it, then scoping and tuning it for each part of your fleet.

Every protection is paired with analytics from the same telemetry your detections run on, showing how often a control would have fired and which users and devices it would have affected. Protections can be scoped to device groups or individual devices, with exemptions for teams that genuinely need a tool, and tuned per rule with exclusions. Phorion ships with default exclusions for known-good behaviour and flags whether a new exclusion is safe before you enable it.

Clipboard Protection follows the same philosophy, with an Audit mode that blocks nothing so you can measure your baseline first.

What incident response capabilities does Phorion provide?

Phorion provides built-in incident response, including a live response terminal, one-click device isolation, process termination and automated response actions, with no add-ons required.

Responders can drop into a secure, audited live shell on any endpoint to collect artifacts and remediate threats, and isolate a compromised device from the network while keeping the Phorion agent connected for investigation. High-confidence detections can trigger automatic containment such as killing processes, isolating devices or running custom scripts.

To investigate, a visual attack graph maps process trees, file access and network activity, and an analyst timeline records actions and findings for post-incident review. See the incident response page.

Visibility & telemetry

What telemetry does Phorion collect?

Phorion collects deep macOS telemetry including process execution, file access, network connections, UnifiedLog entries, TCC service usage, extended file attribute changes and clipboard paste activity.

This telemetry is shaped by Phorion’s own detection engineering: where additional data improves coverage of real-world attacker techniques, it gets built in. That’s why Phorion collects file access events across the board rather than for a handful of paths, records every use of a TCC-protected service, and captures attribute changes used for defence evasion. Phorion ranked #1 in the EDR Telemetry Project as a result.

All of it is available to you as raw data through the hosted SIEM, alongside inventory data such as installed software, extensions, packages and persistence mechanisms.

Can Phorion track IDE extensions, browser extensions and developer packages?

Yes, Phorion inventories IDE extensions, browser extensions and developer packages across your entire Mac fleet.

Phorion monitors VS Code, Cursor and browser extensions, and tracks packages from npm, Homebrew, pip and other package managers. When a malicious extension or compromised package surfaces in the wild, you can instantly identify which endpoints are exposed and respond.

Phorion also maintains a software inventory, maps persistence mechanisms such as launch agents, daemons and login items, tracks macOS patch levels, and assigns each device a real-time health score. See endpoint visibility.

Does Phorion support osquery?

Yes, Phorion has a built-in osquery integration that lets you query your entire fleet with SQL.

Teams use it to run ad-hoc investigations, hunt for indicators of compromise, and examine live endpoint state such as running processes, open files, network connections and persistence mechanisms across many endpoints in seconds. Learn more on the endpoint visibility and incident response pages.

Deployment, performance & privacy

How is Phorion deployed?

Phorion is deployed as a single lightweight agent through your MDM, with zero-touch deployment via Jamf, Kandji or any other MDM.

Phorion is designed to work out of the box without complex configuration and can be deployed in under five minutes. Every customer also receives hands-on rollout support, including MDM profiles, configuration guidance and best practices. See pricing for what’s included.

Which macOS versions does Phorion support?

Phorion supports macOS 12.1 (Monterey) and later, on both Apple silicon and Intel Macs.

Phorion also guarantees day-zero support for every new macOS release, so you never have to hold back operating system upgrades while waiting for your security agent to catch up. Because the team tracks each new release closely (including undocumented Endpoint Security events), new macOS capabilities can be put to work for detection as soon as they ship.

Will Phorion slow down my Macs?

No, Phorion is built to be lightweight, and it includes built-in performance monitoring so you can verify the agent’s CPU and memory impact on every endpoint in real time.

Many vendors limit telemetry to keep their footprint low. Phorion treats performance as an engineering problem rather than a reason to create blind spots: the agent is built natively for macOS with deep platform integration, allowing it to collect and process data others leave behind without degrading the user experience.

This matters most for developers, who tend to disable security tools that slow down builds or drain battery. Read more in Dispelling the myth of performance.

How does Phorion protect user privacy?

Phorion is designed with privacy in mind, using safeguards such as secret scrubbing and privacy-sensitive application blocklists to limit the sensitive data that leaves the endpoint.

Phorion strips secrets from telemetry before it leaves the device, and you can add custom patterns for your own credentials. For Clipboard Protection, the agent never monitors a built-in blocklist of password managers (such as 1Password, Bitwarden and Apple’s Passwords app), applies the same secret redaction to clipboard snippets, and lets administrators reduce snippet length to zero, disabling content capture entirely.

Phorion also offers data residency in multiple regions and is GDPR compliant. Read more about our principles.

Is Phorion GDPR compliant?

Yes. Phorion is GDPR compliant and uses privacy safeguards such as on-device secret scrubbing, privacy-sensitive application blocklists and regional data residency to protect customer data.

Where is Phorion data stored?

Phorion offers data residency in the United States, the United Kingdom and Australia, and you choose the region where your data is stored.

New regions are being added all the time. If you have a data residency requirement that isn’t covered by the current regions, get in touch and the team will work with you to try to make it happen.

Is Phorion SOC 2 compliant?

Yes, Phorion has achieved SOC 2 Type II compliance, audited by independent auditor Insight Assurance.

A SOC 2 Type II report tests both the design and operating effectiveness of controls over an observation period, covering how Phorion secures its infrastructure, manages access, reviews and deploys changes, and handles customer data. The report is available under NDA through the Phorion Trust Portal, and Phorion will be audited annually to maintain it.

Phorion is also GDPR compliant and its agent is Apple notarized. Read the SOC 2 Type II announcement.

Pricing & support

How much does Phorion cost?

Phorion costs $15 per endpoint per month, and every customer gets the complete platform.

That price includes threat detection, endpoint visibility, protections and incident response, plus rollout support, follow-the-sun support and a shared Slack channel. See the pricing page for details.

Why does Phorion cost more than some other endpoint security tools?

Phorion’s price reflects a complete, macOS-dedicated security platform: one per-endpoint price covers detection, prevention, response, visibility and hands-on support that often require several products or higher tiers elsewhere.

For $15 per endpoint per month you get behavioural EDR with industry-leading macOS telemetry, DoubleYou antimalware, Protections such as file access controls and Clipboard Protection, live response and device isolation, a hosted SIEM, osquery, and continuous threat hunting by Phorion’s researchers. Rollout support, follow-the-sun support and a shared Slack channel are included too. Replacing a patchwork of point solutions with a single agent can also lower your total cost of ownership, with fewer vendors to manage and renew.

Phorion can offer volume discounts and is always looking for ways to work with the right customers. Reach out to discuss what could work for your organisation.

Does Phorion have pricing tiers or paid add-ons?

No, Phorion has no pricing tiers and no add-ons: every customer gets every feature from day one.

Tiered pricing often leaves teams on lower tiers missing critical features during an incident, and drags out enterprise negotiations. Phorion avoids that entirely, so your security doesn’t depend on your procurement process. Response capabilities, protections and antimalware are all built in. See pricing.

What support is included with Phorion?

Every Phorion customer gets hands-on rollout support, follow-the-sun support and a shared Slack channel with the Phorion team.

Rollout support covers MDM profiles, configuration guidance and best practices to get you running smoothly. Follow-the-sun coverage means someone is available across time zones, and the shared Slack channel gives you direct access to the team, with no ticket queues.

How do I get started with Phorion?

The best way to get started is to book a demo, where the Phorion team will show you how the platform protects your macOS fleet.

From there, the team will help you plan deployment through your MDM, with hands-on rollout support included for every customer. Review pricing and the platform features in the meantime.

Does Phorion offer a free trial?

Yes. Phorion offers a free evaluation period for qualifying prospective customers, so you can evaluate the complete platform on your own Macs before committing.

To find out whether you qualify, get in touch through the demo form. The team will walk you through the platform and help you set up the evaluation through your MDM.

Still have questions?

Talk to the team behind Phorion.

Book a demo
Let's Talk

See how Phorion protects your macOS fleet

Purpose-built by macOS security researchers. One lightweight agent delivering detection, prevention, and visibility.

Ready to see it in action? Book a demo and we'll show you how Phorion can protect your fleet.

Book a Demo

Error

Expect a personal email from our team.

Pricing About Us Blog