kevmap

TechniquesT1056.003 › AN1322

AN1322 Analytic 1322

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries.</p>
Detects
T1056.003 Web Portal Capture
Part of
DET0480 Detection of Credential Harvesting via Web Portal Modification

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
fs:fsusageFilesystem Access LoggingDC0061 File Modification
macos:unifiedlogsubsystem=com.apple.WebKitDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
WebRootPathSpecify custom web service directories (e.g., /Library/WebServer/Documents/)
AnomalousProcessAlert on web root changes from non-web processes or scripts