Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0555 — Detection Strategy for Event Triggered Execution via emond on macOS
DET0555

Detection Strategy for Event Triggered Execution via emond on macOS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1534 Analytic 1534
macOS

Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.

macos:unifiedlog file create or modify in /etc/emond.d/rules or /private/var/db/emondClients macos:unifiedlog execution of /sbin/emond with child processes launched macos:unifiedlog rule definitions written to emond rule plists macos:unifiedlog command execution triggered by emond (e.g., shell, curl, python)
[PathPrefix] Paths such as `/etc/emond.d/rules/` and `/private/var/db/emondClients` may vary slightly or be symlinked in some setups
[TimeWindow] The time range for correlating rule file creation to emond execution may be tuned based on system performance and usage
[ParentProcessFilter] Defenders may wish to restrict alerts to emond processes not spawned from trusted system update or provisioning tools
[CommandPatternList] List of known suspicious commands or binaries used by adversaries (e.g., reverse shells, persistence scripts)

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0555
STIX ID
x-mitre-detection-strategy--f0ef3932-5f60-4dfc-9725-8639d67349cc
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.