{"id":"T1543.004","name":"Launch Daemon","url":"https://attack.mitre.org/techniques/T1543/004","tactics":["persistence","privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0401","stix_id":"x-mitre-detection-strategy--dcbcea6d-e822-4fe3-b9df-86d4d9cd5667","name":"Detection Strategy for Launch Daemon Creation or Modification (macOS)","url":"https://attack.mitre.org/detectionstrategies/DET0401","analytics":[{"id":"AN1126","stix_id":"x-mitre-analytic--4bb5b68e-1a01-498e-ae39-94f951e01cd9","name":"Analytic 1126","description":"Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry.","url":"https://attack.mitre.org/detectionstrategies/DET0401#AN1126","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launchd spawning processes tied to new or modified LaunchDaemon .plist entries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:launchdaemons","channel":"file_create","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-launchdaemons"},{"name":"fs:launchdaemons","channel":"file_modify","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-launchdaemons"},{"name":"macos:unifiedlog","channel":"launchd loading new LaunchDaemon or changes to existing daemon configuration","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ProgramPathRegex","description":"Regex patterns to match anomalous executable paths or names in .plist files"},{"field":"TimeWindow","description":"Correlation window between file modification and launchd process execution"},{"field":"UserContext","description":"Admin or root context used during daemon installation"},{"field":"UnsignedBinaryFlag","description":"Whether the binary associated with the LaunchDaemon is signed or trusted"}],"live":true,"detection_strategies":["DET0401"],"techniques":["T1543.004"]}],"live":true,"version":"1.0","techniques":["T1543.004"]}],"sigma_rules":[{"id":"65d506d3-fcfe-4071-b4b2-bcefe721bbbb","title":"Potential Persistence Via PlistBuddy","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-02-18","modified":null,"description":"Detects potential persistence activity using LaunchAgents or LaunchDaemons via the PlistBuddy utility","references":["https://redcanary.com/blog/clipping-silver-sparrows-wings/","https://www.manpagez.com/man/8/PlistBuddy/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.001","attack.t1543.004"],"path":"rules/macos/process_creation/proc_creation_macos_persistence_via_plistbuddy.yml","techniques":["T1543.001","T1543.004"],"cves":[]},{"id":"ae9d710f-dcd1-4f75-a0a5-93a73b5dda0e","title":"Launch Agent/Daemon Execution Via Launchctl","author":"Pratinav Chandra","status":"test","level":"medium","date":"2024-05-13","modified":null,"description":"Detects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.001/T1569.001.md","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/","https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html","https://www.loobins.io/binaries/launchctl/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1569.001","attack.t1543.001","attack.t1543.004"],"path":"rules/macos/process_creation/proc_creation_macos_launchctl_execution.yml","techniques":["T1569.001","T1543.001","T1543.004"],"cves":[]},{"id":"e710a880-1f18-4417-b6a0-b5afdf7e3023","title":"Atomic MacOS Stealer - Persistence Indicators","author":"Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital)","status":"experimental","level":"high","date":"2025-11-22","modified":null,"description":"Detects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.\n","references":["https://moonlock.com/amos-backdoor-persistent-access","https://github.com/bobby-tablez/TTP-Threat-Feeds/blob/45398914e631f8372c3a9fbcd339ff65ffff1b17/results/2025/10/20251001-161956-trendmicro-atomic-macos-stealer-(amos).yml#L44"],"logsource":{"product":"macos","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1564.001","attack.t1543.004","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Atomic-MacOS-Stealer/file_event_macos_malware_amos_persistence.yml","techniques":["T1564.001","T1543.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}