Running programs
Who signed each one, where it runs from, what its command line asks for, and whether it mines crypto or talks to a known mining pool.
GhostShield
GhostShield reads what runs on your Mac, what starts on its own, and what got in through the browser or a message — and tells you, with the file and the line, what is worth your attention. It's part of Shields — an optional subscription, separate from DriveScape Pro — and runs on macOS.
Who signed each one, where it runs from, what its command line asks for, and whether it mines crypto or talks to a known mining pool.
Launch agents and daemons, Login Items and background items, login hooks, authorization and input-method plug-ins.
Shell start files (.zshrc and friends) that download and run code, SSH keys that can sign in, sudo rules, the system crontab, hidden programs in your home folder.
Apps in Applications and disk images, installers and programs in Downloads, compared with known malware — including ones you have not opened yet.
Extensions, search and start pages, policies that force them, and sites allowed to send you notifications (“your Mac is infected!” pop-ups).
Mail, Messages, browser history and Downloads from the last 90 days: look-alike sites, links that go somewhere else than they show, requests for codes or payments.
Which programs are online, where they connect — country and network owner, from a table inside the app — and which accept connections from other computers.
Which programs may control your Mac, see the screen, read the keyboard or every file, or use the camera and microphone.
22 macOS protections: SIP, XProtect, Gatekeeper, FileVault, the firewall, updates, sharing and remote access — with how to fix each one.
GhostShield recognises known malware by fingerprints, signing identities and the way each family sets itself up to start. The list is built from public research by security companies, signed by DriveScape, and checked on your Mac before it is used. Downloading it is the only thing GhostShield sends over the internet — and the request carries nothing about your Mac.
Built from research by: ESET · Elastic Security · Moonlock Lab · Jamf Threat Labs · SentinelLabs · Kandji · Objective-See · Huntress · MITRE ATT&CK · Mac Admins (SOFA) · NoCoin list · US Treasury OFAC
When something on your Mac matches, the card says which family and which report it comes from.
Atomic Stealer (AMOS), Odyssey, Cuckoo, Realst, MacSync, SHub, CrashStealer, DigitStealer, Phexia, BeaverTail, Keydnap
KandyKorn, RustBucket, Hidden Risk, TodoSwift, NimDoor, FlexibleFerret, ChillyHell, MacMa, ZuRu, JokerSpy, AppleJeus, ElectroRAT
CloudMensis, DazzleSpy, PasivRobber
EvilQuest (ThiefQuest)
Honkbox, OSAMiner, CpuMeaner, XMRig-based miners
Adload, Pirrit, Shlayer / Bundlore, Genieo, UpdateAgent, MaxOfferDeal
Every finding comes from a written rule or a listed fact, with the file and line it came from.
No files, names, paths or results are uploaded. Ever.
Every change goes through a review list first, and quarantine can be undone.
It is not an antivirus. It shows what it found and why — you decide.
No. It does not guess and it does not delete on its own. It reads your Mac, compares what it finds with written rules and a signed list of known threats, and shows you each fact with its receipt. You decide what to quarantine, and quarantine can be undone.
No. Every check runs on your Mac. The only download is the signed threat database, and that request carries nothing about your Mac.
GhostShield is macOS-only for now. NeuroShield, which audits the AI coding agents on your computer, works on macOS, Windows and Linux.
When new research is published. While Shields is active, the app checks for a newer signed version on its own, and you can see its version, date and sources inside GhostShield under “What We Check”.
Because the disk tools are finished work you buy once, and a threat database is never finished — new Mac malware families keep appearing, and the list has to follow. You pay for that upkeep, and only if you want it.
You can cancel any time through Paddle, and the subscription runs to the end of the period you paid for. When a subscription ends, GhostShield and NeuroShield switch off — the same as when a trial ends. Pro is yours forever and isn't affected. There is one free trial per person.
No. Pro is the disk tools, $8 once. Shields (GhostShield + NeuroShield) is sold separately, and Pro works fully without it. You can run the free GhostShield check without either.
Download DriveScape and run a free check. For the details, the fixes and the background check, Shields is $40 a year or $8 a month. The 7-day free trial takes a card and is charged when it ends, unless you cancel first. One free trial per person.