{"id":"T1548.006","name":"TCC Manipulation","url":"https://attack.mitre.org/techniques/T1548/006","tactics":["privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0534","stix_id":"x-mitre-detection-strategy--f1fdcaa2-7040-4cea-a934-7397566a312b","name":"TCC Database Manipulation via Launchctl and Unprotected SIP","url":"https://attack.mitre.org/detectionstrategies/DET0534","analytics":[{"id":"AN1474","stix_id":"x-mitre-analytic--c0766f2c-e282-44a1-8dcf-1575d77658da","name":"Analytic 1474","description":"Unauthorized modification of TCC.db followed by elevated process execution under a trusted parent (e.g., Finder, SystemUIServer) or via launchctl environment override. Also includes identification of SIP being disabled, which is highly uncommon and a prerequisite for this abuse path.","url":"https://attack.mitre.org/detectionstrategies/DET0534#AN1474","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Modification or replacement of /Library/Application Support/com.apple.TCC/TCC.db or ~/Library/Application Support/com.apple.TCC/TCC.db","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of launchctl with setenv or bootout targeting TCC.db or AppleScript under Finder context","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"System Integrity Protection (SIP) state reported as disabled","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ParentProcessName","description":"May vary across macOS versions and user contexts; defenders can tune for known benign cases."},{"field":"TCCModificationPath","description":"Custom user paths or redirected SQLite DBs may require alternate matching logic."},{"field":"TimeWindow","description":"Temporal proximity between launchctl setenv and subsequent privileged access can be tuned."},{"field":"SIPStateCheckInterval","description":"Frequency of SIP integrity checks may vary based on system hardening policies."}],"live":true,"detection_strategies":["DET0534"],"techniques":["T1548.006"]}],"live":true,"version":"1.0","techniques":["T1548.006"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}