Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0395 — macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection
DET0395

macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1111 Analytic 1111
macOS

Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.

macos:unifiedlog Execution of /usr/libexec/security_authtrampoline or child processes originating from non-trusted binaries triggering credential prompts macos:unifiedlog Calls to AuthorizationExecuteWithPrivileges() observed via Apple System Logger or security_auditing tools macos:unifiedlog User credential prompt events without associated trusted installer package
[BinaryReputationList] Allow list of trusted binaries invoking elevation prompts
[TimeWindow] Temporal correlation threshold between API call and credential prompt
[PromptContextValidation] Heuristic filters to determine whether a prompt context matches known legitimate installers

Detected Techniques

1

Details

MITRE ID
DET0395
STIX ID
x-mitre-detection-strategy--2dd0f2ef-2c31-4b11-a507-91067bb61787
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.