> Source: [sk130652](https://support.checkpoint.com/results/sk/sk130652)

# sk130652 - SandBlast detection and prevention of macOS file types 

| Property | Value |
|----------|-------|
| Solution ID | sk130652 |
| Date Created | 2018-06-28 |
| Last Modified | 2018-07-10 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

SandBlast can detect and prevent macOS file types both locally and in the SandBlast Emulation Cloud.

SandBlast solution includes in Threat Emulation dozens of detection engines. These engines are built to examine file content, similarity to malicious files, utilizing machine learning models, archive extraction, embedded object detection and several static deep scan engines. These capabilities along with the vast intelligence network allow us to provide excellent file analysis of macOS files and classifying them as malicious, benign or possibly un wanted software.

The following macOS file types are supported via SandBlast:

* Application Bundles
* DMG
* Mach-O
* PKG

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
