Techniques › T1211 › AN1635
AN1635 Analytic 1635
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs.</p>
- Detects
- T1211 Exploitation for Stealth
- Part of
- DET0595 Detection Strategy for Exploitation for Stealth
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | Abnormal terminations of com.apple.security.* or 3rd-party security daemons | DC0038 Application Log Content |
| macos:osquery | execve: Unsigned or unnotarized processes launched with high privileges | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
SecurityDaemons | Monitored Apple and third-party EDR/AV daemon names. |
UnsignedProcessThreshold | Number of unsigned high-privilege executions before alerting. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2022-21999 | Microsoft Windows | Mapped |