kevmap

TechniquesT1011.001 › AN1533

AN1533 Analytic 1533

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Observation of blueutil/networksetup commands or low-level APIs toggling Bluetooth or initiating transfers, especially if paired with recent large file read activity by non-GUI processes.</p>
Detects
T1011.001 Exfiltration Over Bluetooth
Part of
DET0554 Detection of Bluetooth-Based Data Exfiltration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogNoneDC0064 Command Execution
macos:osqueryNoneDC0082 Network Connection Creation
macos:osqueryNoneDC0055 File Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ProcessContextLimit to background processes or scripts with no GUI interaction.
PayloadTypeFocus on specific sensitive file types (e.g., zip, docx, keychain db).