Analytics Story: MacOS Post-Exploitation

Description

This analytic story identifies popular MacOS post exploitation tools such as MacPEAS, MacShellSwift, EvilOSX, chainbreaker, etc

Why it matters

These tools allow operators find possible exploits or paths for privilege escalation based on stored credentials, user permissions, kernel version and distro version.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
MacOS LoginHook Persistence Login Hook TTP
MacOS Gatekeeper Bypass Gatekeeper Bypass Anomaly
Socat Remote TCP Connection with Local Echo Disabled Command and Scripting Interpreter, Protocol Tunneling Anomaly
MacOS AppleScript Shell Execution and Compilation AppleScript Anomaly
MacOS Log Removal Indicator Removal TTP
Socat Network Listener Binding an Executable Command and Scripting Interpreter, Protocol Tunneling TTP
MacOS Network Share Discovery Network Share Discovery Anomaly
MacOS Data Chunking Data Transfer Size Limits Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Osquery Results Other osquery:results osquery
Sysmon for Linux EventID 1 Linux icon Linux sysmon:linux Syslog:Linux-Sysmon/Operational

References


Source: GitHub | Version: 2