Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0429 — Detect Modification of macOS Startup Items
DET0429

Detect Modification of macOS Startup Items

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1197 Analytic 1197
macOS

Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution.

macos:unifiedlog launchservices or loginwindow events macos:fsevents /Library/StartupItems/, ~/Library/LaunchAgents/
[directory_path] Specific paths to monitor may differ across macOS versions or enterprise baselines.
[user_context] Different users may have unique LaunchAgents folders—tuning may be required.
[time_window] The correlation time between file creation and process execution may need to be adjusted for boot persistence.
[process_name] Specific startup binaries (e.g., bash, osascript) may vary across implementations.

Detected Techniques

1

Details

MITRE ID
DET0429
STIX ID
x-mitre-detection-strategy--7eb6ccf9-8fb5-4c7d-8a2c-33081c3ddf81
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.