Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0121 — Detection Strategy for T1547.015 – Login Items on macOS
DET0121

Detection Strategy for T1547.015 – Login Items on macOS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0340 Analytic 0340
macOS

Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains.

macos:unifiedlog Post-login execution of unrecognized child process from launchd or loginwindow macos:unifiedlog Modification of backgrounditems.btm or creation of LoginItems subdirectory in .app bundle macos:unifiedlog Invocation of SMLoginItemSetEnabled by non-system or recently installed application macos:unifiedlog AppleScript creating login item via 'System Events' dictionary
[TimeWindow] Correlate file and process activity within a defined interval post-login (e.g., 0–5 minutes)
[UserContext] Distinguish between system users, interactive users, and daemon contexts
[ExecutableAllowlist] Define known-good login items to suppress false positives
[PathRegexExclusion] Exclude common enterprise paths (e.g., Jamf, MDM-managed apps)

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0121
STIX ID
x-mitre-detection-strategy--f3cd8bda-d509-4452-a119-3feebb8f05b6
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.