This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Launch Agent/Daemon Execution Via Launchctl
Original Source:
[Sigma source]
Title:
Launch Agent/Daemon Execution Via Launchctl
Status:
test
Description:
Detects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.001/T1569.001.md
-https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/
-https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/
-https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html
-https://www.loobins.io/binaries/launchctl/
Author:
Pratinav Chandra
Date:
2024-05-13
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.execution'
-'attack.persistence'
-'attack.t1569.001'
-'attack.t1543.001'
-'attack.t1543.004'
Logsource:
category: process_creation
product: macos
Detection:
selection:
Image|endswith
:
'/launchctl'
CommandLine|contains
:
-'submit'
-'load'
-'start'
condition
:
selection
Falsepositives:
-Legitimate administration activities is expected to trigger false positives. Investigate the command line being passed to determine if the service or launch agent are suspicious.
Level:
medium