macOS has a kernel-level sandboxing tool you can use from the terminal. You can leverage it with the audit pattern: use a deny-list profile that lets you run a script once, watch the kernel deny its first write, and decide what to do next.
Oct 7, 2026