kevmap

TechniquesT1684 › AN2036

AN2036 Analytic 2036

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.</p>
Detects
T1684 Social Engineering
Part of
DET0899 Detect Social Engineering

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogExecution of osascript, sh, bash, zsh, installer, openDC0064 Command Execution
NSM:ConnectionsOutbound connection after script or installer launchDC0082 Network Connection Creation
macos:unifiedlogRecent download opened or executedDC0055 File Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
DownloadToExecutionWindowTime between download and launch
InstallerParentAllowlistLegitimate software deployment parents