Summary
Jamf has launched Beacon by Jamf Threat Labs, a premium threat hunting service built specifically for enterprise Mac environments. Announced on July 1, 2026, the service provides organizations with dedicated macOS threat hunters who leverage Apple’s Endpoint Security API for deep visibility into system, user, network, and application activity.
Beacon addresses a persistent gap in enterprise security: most threat hunting teams and tooling are optimized for Windows environments, leaving Mac fleets with comparatively shallow detection coverage. The service offers proactive and retrospective analysis, with the ability to analyze up to a year of historical telemetry data to uncover previously unrecognized threat indicators.
The service is available as an add-on for Jamf for Mac and Jamf for Mac Higher Ed customers, and includes comprehensive remediation reports with actionable recommendations while leaving customers in control of their security policies.
Sources
Commentary
This fills a real blind spot. Enterprise Mac adoption has exploded — especially in engineering, creative, and executive teams — but most security stacks still treat macOS as a second-class citizen. EDR vendors bolt on Mac support as an afterthought, and SOC analysts often lack the macOS internals knowledge to investigate Apple-specific attack chains.
The retrospective analysis capability is particularly interesting. Being able to mine a year of historical telemetry means that if a new macOS threat technique is disclosed tomorrow, Jamf can look backward through existing data to determine if a customer was already compromised. That’s a meaningful advantage over tools that can only detect threats going forward.
