MacOS Gatekeeper Bypass: endpointEndpointNoneversion:3
Detects known MacOS security bypass techniques that may be used to enable malicious code execution.
Specifically monitors for attempts to remove the com.apple.quarantine attribute using xattr, or to disable Gatekeeper protections via spctl --master-disable, both of which can allow untrusted or malicious applications to execute without standard system safeguards.
MacOS Kextload Usage: endpointEndpointNoneversion:3
Detects execution of the kextload command on macOS systems. The kextload utility is used to manually load kernel extensions (KEXTs) into the macOS kernel, which can introduce privileged code at the kernel level.
While legitimate for driver installation and system administration, misuse may indicate attempts to install unauthorized, malicious, or persistence-enabling kernel extensions.
MacOS Osascript Displaying Suspicious User Prompt: endpointEndpointNoneversion:1
The following analytic detects the execution of the macOS osascript utility with AppleScript commands that display a dialog or alert containing potentially deceptive, credential-related, or security-themed content.
Adversaries may abuse osascript to present fake system messages or credential prompts and trick users into disclosing sensitive information.
This detection is based on command-line content and should be reviewed with the parent process, executing user, script content, and surrounding endpoint activity.
MacOS Keychains Dumped: endpointEndpointNoneversion:4
Detects command-line attempts to access or dump macOS Keychain data using native utilities or direct file access.
This includes credential dumping via the `security` utility (e.g. `dump-keychain -d`), bulk certificate export using `security find-certificate`, and direct file copying of Keychain database files using utilities such as `cat`.
Keychain files are located in `~/Library/Keychains/`, `/Library/Keychains/`, and `/Network/Library/Keychains/`.
This technique is commonly associated with post-exploitation credential harvesting, where an attacker with local access seeks to escalate privileges or move laterally by obtaining stored credentials for applications, Wi-Fi networks, system services, and certificates.