diff --git a/detection/execution/unexpected-gatekeeper-approvals-macos.sql b/detection/execution/unexpected-gatekeeper-approvals-macos.sql index 7e18e78..b640b87 100644 --- a/detection/execution/unexpected-gatekeeper-approvals-macos.sql +++ b/detection/execution/unexpected-gatekeeper-approvals-macos.sql @@ -27,6 +27,7 @@ FROM WHERE gap.path NOT LIKE '/Users/%/bin/%' AND gap.path NOT LIKE '/Users/%/rekor-cli' + AND gap.path NOT LIKE '/usr/local/bin/%' AND gap.path NOT LIKE '/Users/%/scorecard-darwin-amd64' AND gap.path NOT LIKE '/Users/%/scorecard-darwin-amd64' AND gap.path NOT LIKE '/Users/%/configure'