kevmap

TechniquesT1037 › AN0313

AN0313 Analytic 0313

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitoring for modification and execution of login hook scripts or LaunchAgents/LaunchDaemons used for persistence.</p>
Detects
T1037 Boot or Logon Initialization Scripts
Part of
DET0112 Boot or Logon Initialization Scripts Detection Strategy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedloglogDC0029 Script Execution
fs:fsusagefileDC0055 File Access
macos:osquerylaunchdDC0041 Service Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
LabelLaunchAgent or LaunchDaemon label name, often environment-specific.
ProgramArgumentsArguments passed to scripts, which may need tuning by environment.
UserContextDistinguish between user login and system startup agents.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-41328Fortinet FortiOSMapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped