kevmap

TechniquesT1606 › AN0721

AN0721 Analytic 0721

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Forged credentials on macOS may be visible through Unified Logs showing abnormal access to Keychain or browser session files. Correlated with anomalous web session usage from Safari or Chrome processes outside typical user context.</p>
Detects
T1606 Forge Web Credentials
Part of
DET0260 Detection Strategy for Forged Web Credentials

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogAccess to Keychain items or browser credential storesDC0067 Logon Session Creation
macos:unifiedlogWeb sessions initiated with newly forged tokensDC0007 Web Credential Usage

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AuthorizedKeychainAppsList applications that normally request Keychain credentials.