Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0288 — Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
DET0288

Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0800 Analytic 0800
macOS

Correlates suspicious removal or modification of the com.apple.quarantine extended attribute, manipulation of LSFileQuarantineEnabled values in Info.plist, and unexpected process execution of unsigned or non-notarized binaries. Also monitors abnormal trust validation failures in unified logs and unusual activity in QuarantineEvents database entries.

macos:unifiedlog xattr -d com.apple.quarantine or similar attribute removal commands macos:unifiedlog Trust validation failures or bypass attempts during notarization and code signing checks macos:osquery Changes to LSFileQuarantineEnabled field in Info.plist
[QuarantineBypassAllowList] Legitimate enterprise update tools or deployment frameworks that may strip quarantine flags
[CertificateAuthorityList] Baseline trusted Apple Developer IDs and enterprise certs used for code signing
[TimeWindow] Time correlation window for xattr modification followed by suspicious process execution

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0288
STIX ID
x-mitre-detection-strategy--62d7a748-dee5-46c7-b61c-77f57f371b4f
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.