Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0265 — Detection Strategy for System Services: Launchctl
DET0265

Detection Strategy for System Services: Launchctl

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0736 Analytic 0736
macOS

Abuse of launchctl to execute or manage Launch Agents and Daemons. Defender perspective: correlation of suspicious plist file creation or modification in LaunchAgents/LaunchDaemons directories with subsequent execution of the launchctl command. Abnormal executable paths (e.g., /tmp, /Shared) or launchctl activity followed by network connections are highly suspicious.

macos:unifiedlog execution of launchctl load/unload/start commands macos:unifiedlog write of plist files in /Library/LaunchAgents or /Library/LaunchDaemons macos:unifiedlog launchctl spawning new processes macos:unifiedlog creation or loading of new launchd services
[MonitoredPaths] Paths to monitor for suspicious plist files, such as /Library/LaunchAgents, /Library/LaunchDaemons, ~/Library/LaunchAgents.
[SuspiciousExecPaths] Uncommon executable paths (e.g., /tmp, /Shared) that should raise alerts when associated with launchctl services.
[TimeWindow] Correlation window for detecting plist file creation and subsequent launchctl execution.

Detected Techniques

1

Execution (1)

Details

MITRE ID
DET0265
STIX ID
x-mitre-detection-strategy--77078baf-96f1-413a-bf5b-96b42486e26c
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.