Analytics Story: MacOS Post-Exploitation

Description

This analytic story identifies popular MacOS post exploitation tools such as MacPEAS, MacShellSwift, EvilOSX, chainbreaker, etc

Why it matters

These tools allow operators find possible exploits or paths for privilege escalation based on stored credentials, user permissions, kernel version and distro version.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
MacOS Log Removal Indicator Removal TTP
MacOS Osascript Executing Interactive Shell AppleScript, Unix Shell Anomaly
MacOS Osascript Executing JavaScript Code With ObjC AppleScript, JavaScript Anomaly
MacOS Gatekeeper Bypass Gatekeeper Bypass Anomaly
Socat Remote TCP Connection with Local Echo Disabled Command and Scripting Interpreter, Protocol Tunneling Anomaly
Socat Network Listener Binding an Executable Command and Scripting Interpreter, Protocol Tunneling TTP
MacOS Network Share Discovery Network Share Discovery Anomaly
MacOS LoginHook Persistence Login Hook TTP
Cisco NVM - Osascript Network Connection for a Long Duration AppleScript, Web Protocols Anomaly
MacOS AppleScript Shell Execution and Compilation AppleScript Anomaly
MacOS Data Chunking Data Transfer Size Limits Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Osquery Results Other osquery:results osquery
Sysmon for Linux EventID 1 Linux icon Linux sysmon:linux Syslog:Linux-Sysmon/Operational
Cisco Network Visibility Module Flow Data Network icon Network cisco:nvm:flowdata:v2 not_applicable

References


Source: GitHub | Version: 2