kevmap

TechniquesT1090 › AN1231

AN1231 Analytic 1231

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>AppleScript, LaunchAgents, or remote login services (ssh, networksetup) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.</p>
Detects
T1090 Proxy
Part of
DET0445 Detection of Proxy Infrastructure Setup and Traffic Bridging

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogNoneDC0032 Process Creation
NSM:Firewallpf firewall logsDC0078 Network Traffic Flow
NSM:Flowconnection attemptsDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TargetDomainIdentify suspicious domains often associated with CDN-routed or anonymized endpoints (e.g., Cloudflare, Fastly).
AppleScriptUsageAlert when AppleScript or Automator tools are used for network tunneling tasks.
LaunchAgentSourceMonitor for LaunchAgents executing proxy tools or dynamic ports.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped