Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0109 — Detection Strategy for Plist File Modification (T1647)
DET0109

Detection Strategy for Plist File Modification (T1647)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0306 Analytic 0306
macOS

Monitor for unexpected modifications of plist files in persistence or configuration directories (e.g., ~/Library/LaunchAgents, ~/Library/Preferences, /Library/LaunchDaemons). Detect when modifications are followed by execution of new or unexpected binaries. Track use of utilities such as defaults, plutil, or text editors making changes to Info.plist files. Correlate file modifications with subsequent process launches or service starts that reference the altered plist.

macos:unifiedlog write: File modifications to *.plist within LaunchAgents, LaunchDaemons, Application Support, or Preferences directories macos:unifiedlog exec: Execution of defaults, plutil, or common editors (vim/nano) targeting plist files macos:unifiedlog exec: Invocation of /usr/bin/defaults write or /usr/bin/plutil modifying plist keys
[MonitoredDirectories] Set of directories where plist modifications are considered suspicious (e.g., ~/Library/LaunchAgents, /Library/LaunchDaemons)
[SuspiciousKeys] List of plist keys associated with evasion or persistence (e.g., LSUIElement, LSEnvironment, ProgramArguments)
[TimeWindow] Temporal correlation window to link plist file modifications with subsequent suspicious process launches

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0109
STIX ID
x-mitre-detection-strategy--0548423e-c893-4474-9e5d-7fdd7c2a0a71
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.