AN0340
Analytic 0340
macOS
Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains.
macos:unifiedlog
Post-login execution of unrecognized child process from launchd or loginwindow
macos:unifiedlog
Modification of backgrounditems.btm or creation of LoginItems subdirectory in .app bundle
macos:unifiedlog
Invocation of SMLoginItemSetEnabled by non-system or recently installed application
macos:unifiedlog
AppleScript creating login item via 'System Events' dictionary
[TimeWindow]
Correlate file and process activity within a defined interval post-login (e.g., 0–5 minutes)
[UserContext]
Distinguish between system users, interactive users, and daemon contexts
[ExecutableAllowlist]
Define known-good login items to suppress false positives
[PathRegexExclusion]
Exclude common enterprise paths (e.g., Jamf, MDM-managed apps)