Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0244 — Detection Strategy for Login Hook Persistence on macOS
DET0244

Detection Strategy for Login Hook Persistence on macOS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0682 Analytic 0682
macOS

Detection of persistent login hooks configured via defaults or plist modifications that result in execution of scripts or binaries at user login, breaking expected parent-child process lineage.

macos:unifiedlog loginwindow or tccd-related entries fs:plist /var/root/Library/Preferences/com.apple.loginwindow.plist
[login_hook_path] Path of script or binary assigned to login hook; may vary by environment
[user_context] Login hook may be applied to specific user accounts; tune by privilege level
[time_window] Correlate plist file modification to execution within a short timeframe
[parent_process_name] Expected parent process (e.g., loginwindow); anomalies can indicate masquerading

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0244
STIX ID
x-mitre-detection-strategy--6aa65bd1-4c0c-4bf7-ba74-ba0d8edd9cb9
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.