Mac下为自定义testosqueryd自动授予全盘访问权限
自定义osquery静默安装并授予全盘访问权限解决方案
1. 重新签名自定义二进制文件
原osqueryd的签名标识符为io.osquery.agent,要实现共存并匹配你的plist标识io.testosquery.agent,必须重新签名自定义的testosqueryd:
- 准备签名证书:使用苹果开发者ID证书(避免Gatekeeper拦截),或自签名证书(仅测试环境使用)。
- 执行重新签名命令(替换证书名称和二进制路径):
codesign -s "你的开发者ID证书名称" -i io.testosquery.agent --deep /path/to/testosqueryd - 验证签名结果:
输出应包含codesign -dr - /path/to/testosquerydidentifier "io.testosquery.agent",确保与plist的Label一致。
2. 配置一致的LaunchDaemon plist
确保plist的Label、程序路径与自定义二进制完全匹配,示例plist内容:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Label</key> <string>io.testosquery.agent</string> <key>Program</key> <string>/opt/testosquery/bin/testosqueryd</string> <key>RunAtLoad</key> <true/> <key>KeepAlive</key> <true/> <key>StandardOutPath</key> <string>/var/log/testosqueryd.stdout</string> <key>StandardErrorPath</key> <string>/var/log/testosqueryd.stderr</string> </dict> </plist>
将plist放置到/Library/LaunchDaemons/io.testosquery.agent.plist,并设置权限:
chown root:wheel /Library/LaunchDaemons/io.testosquery.agent.plist chmod 644 /Library/LaunchDaemons/io.testosquery.agent.plist
3. 静默授予全盘访问权限
macOS的全盘访问权限存储在TCC数据库中,可通过以下两种方式静默配置:
方法1:直接修改TCC.db(需关闭SIP,适用于无MDM环境)
以root权限执行SQL插入命令:
sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db "INSERT OR REPLACE INTO access VALUES('kTCCServiceSystemPolicyAllFiles','io.testosquery.agent',0,1,1,NULL,NULL,NULL,'UNUSED',NULL,0,16777216,NULL,NULL);"
参数说明:
kTCCServiceSystemPolicyAllFiles:指定全盘访问权限服务io.testosquery.agent:匹配签名的标识符- 第二个
1:表示允许权限 - 第三个
1:标记权限为有效状态
方法2:使用TCC配置文件(无需关闭SIP,推荐)
生成TCC配置文件com.testosquery.tcc.plist:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadIdentifier</key> <string>com.testosquery.tcc</string> <key>PayloadType</key> <string>Configuration</string> <key>PayloadVersion</key> <integer>1</integer> <key>PayloadUUID</key> <string>生成一个唯一UUID</string> <key>PayloadDisplayName</key> <string>Testosquery TCC Settings</string> <key>PayloadContent</key> <array> <dict> <key>PayloadType</key> <string>com.apple.TCC.configuration-profile-policy</string> <key>PayloadIdentifier</key> <string>com.testosquery.tcc.policy</string> <key>PayloadUUID</key> <string>生成另一个唯一UUID</string> <key>PayloadVersion</key> <integer>1</integer> <key>Services</key> <dict> <key>SystemPolicyAllFiles</key> <array> <dict> <key>Identifier</key> <string>io.testosquery.agent</string> <key>IdentifierType</key> <string>bundleID</string> <key>Allowed</key> <true/> <key>CodeRequirement</key> <string>identifier "io.testosquery.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "你的证书OU"</string> </dict> </array> </dict> </dict> </array> </dict> </plist>
将配置文件打包成.mobileconfig,然后静默安装:
profiles install -path /path/to/com.testosquery.tcc.mobileconfig
4. 确保原osquery与自定义版本共存
- 安装路径分离:原osquery保留在
/opt/osquery,自定义版本安装到/opt/testosquery,避免文件冲突。 - 服务标识分离:两者的LaunchDaemon plist分别使用
io.osquery.agent和io.testosquery.agent作为Label,启动后可通过launchctl list | grep osquery确认两个服务独立运行。 - 日志分离:各自配置独立的日志输出路径,避免日志混淆。
内容的提问来源于stack exchange,提问作者User0987
相关产品推荐
相关产品推荐

