Skip to content

Glossary

Gatekeeper

The macOS check, implemented by syspolicyd, that assesses quarantined code at first launch: signature, Developer ID, notarization, XProtect.

Gatekeeper is implemented by syspolicyd. On the first launch of quarantined code it checks the signature, Developer ID, notarization and XProtect. The quarantine attribute is what brings a file into scope. From macOS 15 the Control-click bypass is gone; overrides go through System Settings.

Gatekeeper leaves traces in two places. An approval sets the 0x0040 bit in the item's quarantine flags, and a refusal is written to .LastGKReject, which keeps only the most recent rejection. Neither is a complete history of Gatekeeper decisions, so combine them with the download timeline and other system artifacts. See .LastGKReject and Gatekeeper evidence.