{"id":"T1564.009","name":"Resource Forking","url":"https://attack.mitre.org/techniques/T1564/009","tactics":["stealth"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0584","stix_id":"x-mitre-detection-strategy--0f320fd9-cf15-4fd6-bcb3-c3a52760fe88","name":"Detection Strategy for Resource Forking on macOS","url":"https://attack.mitre.org/detectionstrategies/DET0584","analytics":[{"id":"AN1609","stix_id":"x-mitre-analytic--619804e7-5ae7-4c6e-b1bb-e1d10a22cc87","name":"Analytic 1609","description":"Unexpected creation or modification of files with `com.apple.ResourceFork` extended attributes containing unusually large or non-standard data. Defender perspective: detection of resource forks in contexts where they are uncommon, especially when paired with process execution or network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0584#AN1609","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"File creation or modification with com.apple.ResourceFork extended attribute","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of commands like `ls -l@`, `xattr -l`, or custom tools interacting with resource forks","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Process creation involving binaries interacting with resource fork data","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ResourceForkSizeThreshold","description":"Adjust thresholds for 'unusually large' resource fork data based on baseline usage in the environment."},{"field":"MonitoredDirectories","description":"Scope monitoring to sensitive directories such as /Users, /Applications, or temporary paths."},{"field":"CorrelatedActivityWindow","description":"Time window for correlating resource fork activity with subsequent execution or network activity."}],"live":true,"detection_strategies":["DET0584"],"techniques":["T1564.009"]}],"live":true,"version":"1.0","techniques":["T1564.009"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}