PUBLIC DEMO · sample Battle Scout · run Innsegall on your Macintosh for your own receipt

Innsegall · Battle Scout

You're clear

The mist clears. You're clear.

Solas SUH-lussLight

Tha thu ceart gu leòr ha hoo kyart goo LYORYou're okay enough

We walked 13 paths on your Mac. 13 came back clear. You're okay tonight.

Breathe. Nothing here needs you tonight.

Sep 9, 2026, 11:35 PM · Is my Macintosh okay? · macOS 14.0 (demo) · ✓ 13 ⚠ 0 ✗ 0

Tap a tier to jump to that section

13 clear · 0 review · 0 escalate · highlighted tier matches today's verdict

Voyage chart

Innse Gall sea map · each star is a check. North is calmer water.

48 voyages 30 mean health 16 now
100 75 50 25 ALTITUDE · VOYAGE HEALTH Rougher seas lately Sep 5, 11:24 PM · FIX_LIST · health 72 Sep 5, 11:24 PM · ESCALATE · health 22 Sep 5, 11:24 PM · FIX_LIST · health 75 Sep 5, 11:24 PM · FIX_LIST · health 75 Sep 5, 11:24 PM · FIX_LIST · health 75 Sep 5, 11:24 PM · ESCALATE · health 22 Sep 5, 11:24 PM · FIX_LIST · health 72 Sep 6, 1:15 AM · FIX_LIST · health 75 Sep 6, 1:21 AM · FIX_LIST · health 75 Sep 6, 1:23 AM · LIKELY_OK · health 100 Sep 6, 1:24 AM · LIKELY_OK · health 100 Sep 6, 1:28 AM · LIKELY_OK · health 100 Sep 6, 1:42 AM · ESCALATE · health 16 Sep 6, 1:43 AM · ESCALATE · health 16 Sep 6, 3:03 AM · ESCALATE · health 16 Sep 6, 3:04 AM · ESCALATE · health 16 Sep 6, 4:33 AM · ESCALATE · health 16 Sep 6, 4:35 AM · ESCALATE · health 16 Sep 6, 4:40 AM · ESCALATE · health 16 Sep 6, 4:49 AM · ESCALATE · health 16 Sep 6, 5:19 AM · ESCALATE · health 16 Sep 6, 5:21 AM · ESCALATE · health 16 Sep 6, 5:26 AM · ESCALATE · health 16 Sep 6, 5:40 AM · ESCALATE · health 16 Sep 6, 1:47 PM · ESCALATE · health 16 Sep 6, 1:48 PM · ESCALATE · health 16 Sep 6, 2:02 PM · ESCALATE · health 16 Sep 6, 2:12 PM · ESCALATE · health 16 Sep 6, 2:16 PM · ESCALATE · health 16 Sep 6, 2:18 PM · ESCALATE · health 16 Sep 6, 6:35 PM · ESCALATE · health 16 Sep 6, 6:36 PM · ESCALATE · health 16 Sep 6, 6:37 PM · ESCALATE · health 16 Sep 6, 6:38 PM · ESCALATE · health 16 Sep 6, 6:50 PM · ESCALATE · health 16 Sep 6, 6:57 PM · ESCALATE · health 16 Sep 6, 6:58 PM · ESCALATE · health 16 Sep 6, 7:00 PM · ESCALATE · health 16 Sep 6, 11:08 PM · ESCALATE · health 16 Sep 6, 11:23 PM · ESCALATE · health 16 Sep 7, 12:05 AM · ESCALATE · health 16 Sep 7, 1:27 AM · ESCALATE · health 16 Sep 7, 1:34 AM · ESCALATE · health 16 Sep 7, 2:05 AM · ESCALATE · health 16 Sep 7, 2:32 AM · ESCALATE · health 16 Sep 7, 2:35 AM · ESCALATE · health 16 Sep 7, 2:36 AM · ESCALATE · health 16 Sep 7, 2:37 AM · ESCALATE · health 16 Sep 5 Sep 7 N calm
Clear longship Review glass Horn claymore

Three patterns worth knowing. None of them mean you're infected · they mean know the shape of the fog.

As of 2026-09-06 · Read on the Innsegall blog →

Fake installers (Contagious Interview)

Fourteen trojanized DMG/PKG files posing as Sketch, Bartender, The Unarchiver, and similar. Unsigned bundles hide a `.macos` binary or preinstall scripts, then drop OtterCookie · a RAT that grabs browser creds, clipboard, and wallet data.

Innsegall: If you installed software from a recruiter link or a DMG that asked you to remove quarantine manually · run I clicked a suspicious link and Sound the Horn if anything feels off.

Jamf Threat Labs

Screen Sharing bypass (CVE-2026-65400)

Apple patched in August, but NCSC-NL and Microsoft still see internet-exposed Macs (port 5900) hit for root access and cryptominers. The bug skips real authentication on Screen Sharing.

Innsegall: Turn off Screen Sharing unless you need it. Patch to macOS 26.6.1, 15.7.9, or 14.8.9+. We check sharing exposure in hygiene runs.

NCSC-NL / Huntress

Rust crate supply chain (Rustbot)

Malicious releases on crates.io (Aug 20 window) shipped Rustbot on macOS · launch agent persistence, SSH keys, cloud creds, browser stores.

Innsegall: Developers: if you built Rust projects that day, treat the machine as worth a project safe pass · not panic, evidence.

IRU

No deeds required tonight. Keep this writ if you want proof the scout walked the road.

Nothing flagged.

Every check that could warn or fail came back clean. Solas on the road.

No horn needed.

No checks flagged for escalation. You're not in horn territory tonight.

Solas reads this scout · no Terminal, no copy-paste. Ask a question below or tap Sound the Horn for escalation help.

Solas is reading your Battle Scout…

Here's what your scout found · plain English, no jargon.

**The mist clears. You're clear.** · We walked 13 paths on your Mac. 13 came back clear. You're okay tonight.

Scout tally: 13 clear · 0 review · 0 escalate.

· Solas from your Battle Scout. Live help at innsegall.com when you're online · otherwise this summary is instant from your card.

Live Solas: up to 3 questions per scout when online · instant summary from this card when offline.

Clear 13 checks passed · full check log

Each line shows what we looked at and what we did not cover · expand any row for plain-language limits.

  • Launch ghostsNo unexpected login items flagged.
    What we looked at · limits

    Looked at Startup lists (LaunchAgents, LaunchDaemons, login items) that point at apps or files that are missing

    Does not cover Apps that still launch but behave badly, or kernel-level malware

    Why it matters Broken launch items slow login and are a common place scareware hides after you delete the main app · Why this check matters

  • Adware markersNo known scareware patterns in common spots.
    What we looked at · limits

    Looked at Known adware file names, folders, and browser-extension patterns left on disk

    Does not cover Brand-new malware with no known signature, or threats only in memory

    Why it matters Fake virus popups often leave named leftovers · finding them explains odd browser behavior · Why this check matters

  • Hosts fileHosts file looks ordinary.
    What we looked at · limits

    Looked at Your Mac's hosts file for unexpected redirects to sketchy domains

    Does not cover DNS changes made only on your router or phone, or VPN-only routing

    Why it matters Scareware sometimes edits hosts to lock you onto their "support" pages · What the scout does and does not do

  • DNS resolversResolver settings read clean.
    What we looked at · limits

    Looked at Which DNS servers your Mac is set to use (Wi‑Fi and Ethernet)

    Does not cover DNS on other devices, or encrypted DNS inside a browser only

    Why it matters Fake cleaners often switch DNS so they can intercept or nag you on every site · Why this check matters

  • System proxyNo suspicious proxy hijack.
    What we looked at · limits

    Looked at System-wide web proxy settings that could funnel traffic through a stranger

    Does not cover Browser-only extensions, or corporate proxies your IT installed on purpose

    Why it matters Unexpected proxies are a classic persistence trick after scare popups · Why this check matters

  • GatekeeperGatekeeper enabled as expected.
    What we looked at · limits

    Looked at Whether macOS Gatekeeper and quarantine protections are turned on as expected

    Does not cover Whether every app you run is trustworthy · only whether core guards are enabled

    Why it matters Disabled Gatekeeper makes it easier to run downloaded scareware installers · What the scout does and does not do

  • Security softwareNo conflicting scareware tools detected.
    What we looked at · limits

    Looked at Whether known security tools (Malwarebytes, etc.) are installed and responding

    Does not cover Full scans, license status, or whether those tools found anything today

    Why it matters Knowing what protection you already have avoids duplicate panic subscriptions · What the scout does and does not do

  • Firefox profileExtensions within normal range.
    What we looked at · limits

    Looked at Firefox profiles for suspicious extensions, search hijacks, and odd home pages

    Does not cover Safari or Chrome, or activity inside private windows we cannot see

    Why it matters After a bad link, browsers are often the first place redirects and spam extensions land · Why this check matters

  • Safari profileSafari extensions look familiar.
    What we looked at · limits

    Looked at Safari extensions and homepage/search settings for obvious hijacks

    Does not cover Firefox or Chrome, or iCloud-synced settings on other devices

    Why it matters Safari is the default browser · scare pages often target it first on Mac · Why this check matters

  • Chrome profileChrome extensions within normal range.
    What we looked at · limits

    Looked at Chrome profiles for suspicious extensions, policies, and search overrides

    Does not cover Other browsers, or Chrome on a different user account

    Why it matters Extension spam after a scare popup usually shows up as odd Chrome behavior · Why this check matters

  • Login itemsLogin items match what you'd expect.
    What we looked at · limits

    Looked at Items set to open automatically when you log in (System Settings list)

    Does not cover Background services that do not appear in Login Items, or iCloud-only apps

    Why it matters Mystery login items are a common "why is my Mac slow?" clue after scareware · Why this check matters

  • Recent installsNo surprise installers in the last week.
    What we looked at · limits

    Looked at Apps and packages installed in roughly the last seven days

    Does not cover Installs older than a week, or drag-and-drop apps with no installer record

    Why it matters The thing you installed right after the popup is often the actual trouble · What the scout does and does not do

  • Configuration profilesNo unknown MDM or profiles.
    What we looked at · limits

    Looked at Configuration and MDM profiles that can lock settings or install remote management

    Does not cover Profiles your employer installed on a work Mac you already expect

    Why it matters Unexpected profiles can mean someone else controls settings on your personal Mac · Why this check matters

A clear scout is honest about its lane. Passing these checks means we did not see common scareware leftovers in the places we read · not that your Mac is invulnerable forever.

  • Real-time malware scanning, removal, or quarantine of active threats
  • Whether someone else is reading your email, iCloud, or bank accounts right now
  • Network traffic, keystrokes, or screen capture while you use the Mac
  • Windows, Linux, iPhone, or iPad (Macintosh only today)
  • Guaranteed proof that nothing bad will ever happen later

Read the full lay of the land on innsegall.com