kevmap

TechniquesT1111 › AN0689

AN0689 Analytic 0689

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Processes accessing TCC-protected input APIs or polling HID services without user interaction, or dynamically loaded keylogging frameworks using accessibility privileges</p>
Detects
T1111 Multi-Factor Authentication Interception
Part of
DET0246 Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogcom.apple.securityd, com.apple.tccdDC0021 OS API Execution
macos:osqueryquery: process_events, launchd, and tcc.db accessDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AccessibilityAPIUsageDetection of programs requesting access to input monitoring (e.g., CGEventTap)
TCCBypassAttemptAlert if TCC settings are altered or bypassed
SignedBinaryCheckTunable based on developer signing status (legitimate software vs unsigned)