Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0335 — Detect Abuse of XPC Services (T1559.003)
DET0335

Detect Abuse of XPC Services (T1559.003)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0948 Analytic 0948
macOS

Detects anomalous use of macOS XPC services for code execution. Monitors for processes invoking privileged XPC daemons with abnormal parameters, unexpected binaries communicating over NSXPCConnection, or helper tools executing code outside of their expected parent process lineage. Correlates process access attempts to system-level daemons, privilege escalations via XPC misconfigurations, and injection of malicious payloads through inter-process communication.

macos:unifiedlog Unexpected NSXPCConnection calls by non-Apple-signed or abnormal binaries macos:unifiedlog execve: Helper tools invoked through XPC executing unexpected binaries macos:unifiedlog XPC messages requesting privileged actions from untrusted or unsigned clients
[AllowedXPCClients] Maintain allowlist of binaries permitted to invoke specific XPC services to minimize false positives.
[TimeWindow] Threshold for correlating abnormal XPC requests with subsequent privilege escalation or process creation.
[UnsignedBinaryAlertLevel] Adjust sensitivity of alerts for unsigned or non-Apple-signed clients initiating XPC communication.

Detected Techniques

1

Details

MITRE ID
DET0335
STIX ID
x-mitre-detection-strategy--a92f4b5f-9d0d-461f-8581-a50975f5e07a
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.