Local System Accounts Discovery - MacOs

 Original Source: [Sigma source]
Title: Local System Accounts Discovery - MacOs
Status: test
Description:Detects enumeration of local system accounts on MacOS systems. This can be used by attackers to identify accounts for lateral movement or privilege escalation.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1087.001/T1087.001.md
  -https://ss64.com/osx/dscl.html
  -https://ss64.com/mac/dscacheutil.html
Author: Alejandro Ortuno, oscd.community
Date: 2020-10-08
modified:2026-07-07
Tags:
  • -'attack.discovery'
  • -'attack.t1087.001'
Logsource:
  • category: process_creation
  • product: macos
Detection:
  selection_dscl:
    Image|endswith: '/dscl'
    CommandLine|contains|all:
      -'list'
      -'/users'

  selection_dscacheutil:
    Image|endswith: '/dscacheutil'
    CommandLine|contains|all:
      -'-q'
      -'user'

  selection_root:
    CommandLine|contains: ''*:0:''
  selection_passwd_sudo:
    Image|endswith:
      -'/cat'
      -'/awk'
      -'/grep'

    CommandLine|contains:
      -'/etc/passwd'
      -'/etc/sudoers'

  selection_id:
    Image|endswith: '/id'
  selection_lsof:
    Image|endswith: '/lsof'
    CommandLine|contains: '-u'
  selection_logged_in_users:
    Image|endswith:
      -'/who'
      -'/w'
      -'/users'
      -'/last'

  selection_home_dir_listing:
    Image|endswith: '/ls'
    CommandLine|endswith:
      -'/Users'
      -'/Users''
      -'/Users"'

  selection_loginwindow_prefs:
    Image|endswith:
      -'/defaults'
      -'/plutil'

    CommandLine|contains: 'com.apple.loginwindow'
  condition:1 of selection*
Falsepositives:
  -Legitimate administration activities
Level: low