Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0434 — Detection of Launch Agent Creation or Modification on macOS
DET0434

Detection of Launch Agent Creation or Modification on macOS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1208 Analytic 1208
macOS

Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login.

macos:unifiedlog launchctl load or boot-time plist registration fs:fsusage write or chmod to ~/Library/LaunchAgents/*.plist fs:fsusage modification of existing LaunchAgents plist macos:osquery detection of new launch agents with suspicious paths or unsigned binaries
[PlistDirectoryList] Monitored directories (e.g., `/Library/LaunchAgents`, `~/Library/LaunchAgents`) for plist drops
[PlistKeyMonitor] Monitored keys such as `RunAtLoad`, `KeepAlive`, or `ProgramArguments` for policy alignment
[ExecutablePathPattern] Patterns used to detect execution from non-standard or suspicious locations like `/tmp`, `/var`, or `/Users/Shared`
[UnsignedBinaryAlert] Raise alerts if the binary referenced in the Launch Agent is unsigned or unverified
[UserContextScope] List of users whose LaunchAgents are considered high-sensitivity (e.g., admins)

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0434
STIX ID
x-mitre-detection-strategy--4dbd7441-627f-4d5a-a060-28fe6a8cbb9e
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.