kevmap

TechniquesT1212 › AN0495

AN0495 Analytic 0495

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.</p>
Detects
T1212 Exploitation for Credential Access
Part of
DET0174 Detection Strategy for Exploitation for Credential Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogopendirectoryd crashes or abnormal authentication errorsDC0038 Application Log Content
macos:osqueryexecve: Processes unexpectedly invoking Keychain or authentication APIsDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
WatchedAPIsList of authentication and Keychain-related APIs to monitor for unauthorized access.
CrashCorrelationWindowTime window for correlating authentication service crashes with subsequent suspicious access.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-22948VMware vCenter ServerMapped
CVE-2024-53704SonicWall SonicOSMapped
CVE-2025-48927TeleMessage TM SGNLMapped
CVE-2025-48928TeleMessage TM SGNLMapped