There are so many options, from so many different security perspectives, that analysis paralysis is a real issue.
Obviously it can detect malware if there’s a connection to some weird site, but it’s more like a bonus than a reliable test.
If you need to block FS access, then per app containers or VMs are the way to go. The container/VM sandboxes your files, and Little Snitch can then manage externa connectivity (you might still want to allow connection to some legit domains—-but maybe not github.com as that can be use to upload your data. I meant something like updates.someapp.com)
I got lazy
Time to crank the paranoidmeter up again
ty
Seems a little excessive, but here we are.