Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0125 — Detect persistence via reopened application plist modification (macOS)
DET0125

Detect persistence via reopened application plist modification (macOS)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0349 Analytic 0349
macOS

Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login.

macos:unifiedlog Execution of process launched via loginwindow session restore fs:filesystem Modification or creation of files matching 'com.apple.loginwindow.*.plist' in ~/Library/Preferences/ByHost macos:unifiedlog LoginWindow context with associated PID linked to reopened plist paths macos:endpointsecurity es_event_file_rename_t or es_event_file_write_t
[UserContext] Restrict to targeted users or unexpected users writing to plist
[FilePathPattern] Allow tuning for alternative persistence paths or directory redirection
[TimeWindow] Correlate plist write and process execution within logon window
[BinaryAnomalyScore] Optional scoring of launched binary based on code signing, entropy, and known safe apps

Detected Techniques

1

Details

MITRE ID
DET0125
STIX ID
x-mitre-detection-strategy--5ac0e527-2ebd-44a1-8d87-4de8463b761c
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.