{"id":"T1543.001","name":"Launch Agent","url":"https://attack.mitre.org/techniques/T1543/001","tactics":["persistence","privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0434","stix_id":"x-mitre-detection-strategy--4dbd7441-627f-4d5a-a060-28fe6a8cbb9e","name":"Detection of Launch Agent Creation or Modification on macOS","url":"https://attack.mitre.org/detectionstrategies/DET0434","analytics":[{"id":"AN1208","stix_id":"x-mitre-analytic--441bfb28-3fe5-410b-93a5-2280a7f19dad","name":"Analytic 1208","description":"Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login.","url":"https://attack.mitre.org/detectionstrategies/DET0434#AN1208","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launchctl load or boot-time plist registration","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"write or chmod to ~/Library/LaunchAgents/*.plist","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsusage"},{"name":"fs:fsusage","channel":"modification of existing LaunchAgents plist","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"detection of new launch agents with suspicious paths or unsigned binaries","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"PlistDirectoryList","description":"Monitored directories (e.g., `/Library/LaunchAgents`, `~/Library/LaunchAgents`) for plist drops"},{"field":"PlistKeyMonitor","description":"Monitored keys such as `RunAtLoad`, `KeepAlive`, or `ProgramArguments` for policy alignment"},{"field":"ExecutablePathPattern","description":"Patterns used to detect execution from non-standard or suspicious locations like `/tmp`, `/var`, or `/Users/Shared`"},{"field":"UnsignedBinaryAlert","description":"Raise alerts if the binary referenced in the Launch Agent is unsigned or unverified"},{"field":"UserContextScope","description":"List of users whose LaunchAgents are considered high-sensitivity (e.g., admins)"}],"live":true,"detection_strategies":["DET0434"],"techniques":["T1543.001"]}],"live":true,"version":"1.0","techniques":["T1543.001"]}],"sigma_rules":[{"id":"65d506d3-fcfe-4071-b4b2-bcefe721bbbb","title":"Potential Persistence Via PlistBuddy","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-02-18","modified":null,"description":"Detects potential persistence activity using LaunchAgents or LaunchDaemons via the PlistBuddy utility","references":["https://redcanary.com/blog/clipping-silver-sparrows-wings/","https://www.manpagez.com/man/8/PlistBuddy/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.001","attack.t1543.004"],"path":"rules/macos/process_creation/proc_creation_macos_persistence_via_plistbuddy.yml","techniques":["T1543.001","T1543.004"],"cves":[]},{"id":"ae9d710f-dcd1-4f75-a0a5-93a73b5dda0e","title":"Launch Agent/Daemon Execution Via Launchctl","author":"Pratinav Chandra","status":"test","level":"medium","date":"2024-05-13","modified":null,"description":"Detects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.001/T1569.001.md","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/","https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html","https://www.loobins.io/binaries/launchctl/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1569.001","attack.t1543.001","attack.t1543.004"],"path":"rules/macos/process_creation/proc_creation_macos_launchctl_execution.yml","techniques":["T1569.001","T1543.001","T1543.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}