Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0401 — Detection Strategy for Launch Daemon Creation or Modification (macOS)
DET0401

Detection Strategy for Launch Daemon Creation or Modification (macOS)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1126 Analytic 1126
macOS

Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry.

macos:unifiedlog launchd spawning processes tied to new or modified LaunchDaemon .plist entries fs:launchdaemons file_create fs:launchdaemons file_modify macos:unifiedlog launchd loading new LaunchDaemon or changes to existing daemon configuration
[ProgramPathRegex] Regex patterns to match anomalous executable paths or names in .plist files
[TimeWindow] Correlation window between file modification and launchd process execution
[UserContext] Admin or root context used during daemon installation
[UnsignedBinaryFlag] Whether the binary associated with the LaunchDaemon is signed or trusted

Detected Techniques

1

Details

MITRE ID
DET0401
STIX ID
x-mitre-detection-strategy--dcbcea6d-e822-4fe3-b9df-86d4d9cd5667
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.