Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0584 — Detection Strategy for Resource Forking on macOS
DET0584

Detection Strategy for Resource Forking on macOS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1609 Analytic 1609
macOS

Unexpected creation or modification of files with `com.apple.ResourceFork` extended attributes containing unusually large or non-standard data. Defender perspective: detection of resource forks in contexts where they are uncommon, especially when paired with process execution or network activity.

macos:unifiedlog File creation or modification with com.apple.ResourceFork extended attribute macos:unifiedlog Execution of commands like `ls -l@`, `xattr -l`, or custom tools interacting with resource forks macos:unifiedlog Process creation involving binaries interacting with resource fork data
[ResourceForkSizeThreshold] Adjust thresholds for 'unusually large' resource fork data based on baseline usage in the environment.
[MonitoredDirectories] Scope monitoring to sensitive directories such as /Users, /Applications, or temporary paths.
[CorrelatedActivityWindow] Time window for correlating resource fork activity with subsequent execution or network activity.

Detected Techniques

1

Details

MITRE ID
DET0584
STIX ID
x-mitre-detection-strategy--0f320fd9-cf15-4fd6-bcb3-c3a52760fe88
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.