{"id":"T1546.005","name":"Trap","url":"https://attack.mitre.org/techniques/T1546/005","tactics":["privilege-escalation","persistence"],"platforms":["macOS","Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0369","stix_id":"x-mitre-detection-strategy--07fb6847-efcb-426e-9344-bfc9dfcdebd4","name":"Detection Strategy for Event Triggered Execution via Trap (T1546.005)","url":"https://attack.mitre.org/detectionstrategies/DET0369","analytics":[{"id":"AN1038","stix_id":"x-mitre-analytic--d1d19568-2b59-4d44-9744-22d7304d2200","name":"Analytic 1038","description":"Correlate file modifications in shell startup scripts (e.g., .bashrc, .profile) with embedded `trap` commands and observe if those changes are followed by the unexpected execution of child processes when terminal signals (e.g., SIGINT) are triggered. Use contextual linking with user session activity to detect privilege misuse.","url":"https://attack.mitre.org/detectionstrategies/DET0369#AN1038","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"Modification of user shell profile or trap registration via echo/redirection (e.g., echo \"trap 'malicious_cmd' INT\" >> ~/.bashrc)","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TargetShellFilePath","description":"The path to user profile scripts (e.g., ~/.bashrc, ~/.zshrc); may differ by distro or shell type."},{"field":"SignalTrapName","description":"Trap signal (e.g., INT, HUP, TERM) can be environment-specific or attacker-tuned to evade."},{"field":"TimeWindow","description":"Temporal threshold to correlate trap insertion and process execution (e.g., 10s-5min)"}],"live":true,"detection_strategies":["DET0369"],"techniques":["T1546.005"]},{"id":"AN1039","stix_id":"x-mitre-analytic--99c42b1f-1716-413b-8c23-5f7e1d997ab2","name":"Analytic 1039","description":"Detect unauthorized `trap` command registrations in shell startup files (e.g., .zprofile, .bash_profile, .zshrc) followed by execution chains during user terminal interaction. Use Unified Logs and EDR telemetry to correlate shell command parsing and process tree anomalies.","url":"https://attack.mitre.org/detectionstrategies/DET0369#AN1039","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Command line containing `trap` or `echo 'trap` written to login shell files","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"File write or append to .zshrc, .bash_profile, .zprofile, etc.","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"LoginShellConfigPaths","description":"Startup files vary by shell (.bash_profile, .zshrc, etc.)"},{"field":"TrapCommandLengthThreshold","description":"Short benign traps may differ from longer/multi-command malicious traps"},{"field":"ParentProcessAnomalyThreshold","description":"Score or detect if new child process deviates from shell’s typical behavior"}],"live":true,"detection_strategies":["DET0369"],"techniques":["T1546.005"]}],"live":true,"version":"1.0","techniques":["T1546.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}