Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0534 — TCC Database Manipulation via Launchctl and Unprotected SIP
DET0534

TCC Database Manipulation via Launchctl and Unprotected SIP

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1474 Analytic 1474
macOS

Unauthorized modification of TCC.db followed by elevated process execution under a trusted parent (e.g., Finder, SystemUIServer) or via launchctl environment override. Also includes identification of SIP being disabled, which is highly uncommon and a prerequisite for this abuse path.

macos:unifiedlog Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond macos:unifiedlog Modification or replacement of /Library/Application Support/com.apple.TCC/TCC.db or ~/Library/Application Support/com.apple.TCC/TCC.db macos:unifiedlog Execution of launchctl with setenv or bootout targeting TCC.db or AppleScript under Finder context macos:unifiedlog System Integrity Protection (SIP) state reported as disabled
[ParentProcessName] May vary across macOS versions and user contexts; defenders can tune for known benign cases.
[TCCModificationPath] Custom user paths or redirected SQLite DBs may require alternate matching logic.
[TimeWindow] Temporal proximity between launchctl setenv and subsequent privileged access can be tuned.
[SIPStateCheckInterval] Frequency of SIP integrity checks may vary based on system hardening policies.

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0534
STIX ID
x-mitre-detection-strategy--f1fdcaa2-7040-4cea-a934-7397566a312b
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.