MacOS Osascript Executing Interactive Shell: endpointEndpointNoneversion:1
This analytic detects the macOS osascript utility being used with an interactive Bash invocation, identified by the presence
of "bash -i" in the command line.
Adversaries may abuse osascript and AppleScript's shell execution capabilities to launch
interactive shells, establish remote access, or execute post-exploitation commands.
MacOS Gatekeeper Bypass: endpointEndpointNoneversion:3
Detects known MacOS security bypass techniques that may be used to enable malicious code execution.
Specifically monitors for attempts to remove the com.apple.quarantine attribute using xattr, or to disable Gatekeeper protections via spctl --master-disable, both of which can allow untrusted or malicious applications to execute without standard system safeguards.
Socat Remote TCP Connection with Local Echo Disabled: endpointEndpointNoneversion:1
The following analytic detects execution of the socat utility with a remote TCP or OpenSSL connection and local terminal echo disabled.
This configuration may be used for interactive terminal sessions, password handling, automation, or network debugging.
When observed in an unexpected context, such as execution by an unusual parent process or connection to an untrusted endpoint, it may indicate suspicious remote access activity.
Cisco NVM - Osascript Network Connection for a Long Duration: endpointEndpointNoneversion:1
This analytic detects the usage of the Utility osascript on a macOS device initiated a network connection lasting longer than 10 minutes (600 seconds).
Adversaries may abuse osascript and AppleScript shell execution to establish long-lived command-and-control or remote connections.
Socat Network Listener Binding an Executable: endpointEndpointNoneversion:1
The following analytic detects the execution of the socat utility with command-line arguments that configure a TCP or OpenSSL listener and bind an executable to incoming connections.
Socat is a legitimate network utility, but this behavior may be used to expose executables, establish bind shells, facilitate remote command execution, or support lateral movement.
MacOS Data Chunking: endpointEndpointNoneversion:4
The following analytic detects suspicious data chunking activities that involve the use of split or dd, potentially indicating an attempt to evade detection by breaking large files into smaller parts.
Attackers may use this technique to bypass size-based security controls, facilitating the covert exfiltration of sensitive data.
By monitoring for unusual or unauthorized use of these commands, this analytic helps identify potential data exfiltration attempts, allowing security teams to intervene and prevent the unauthorized transfer of critical information from the network.
MacOS Osascript Executing JavaScript Code With ObjC: endpointEndpointNoneversion:1
This analytic detects the macOS osascript utility executing JavaScript for Automation (JXA) code, identified by
the "-l JavaScript" interpreter flag, with references to the Objective-C bridge. Adversaries may abuse JXA and
Objective-C APIs to interact with macOS applications, access native system functionality, execute commands, or
perform post-exploitation activity.
MacOS LoginHook Persistence: endpointEndpointNoneversion:3
Identifies attempts to configure a macOS LoginHook via the defaults utility. LoginHooks enable automatic execution of a script or program upon user login and have historically been abused for persistence.
Creation or modification of this setting may indicate an attempt to establish startup execution outside standard LaunchAgent mechanisms.
MacOS Network Share Discovery: endpointEndpointNoneversion:3
Identifies execution of network share enumeration commands (smbutil, showmount) that can be leveraged by adversaries to discover accessible SMB and NFS resources, supporting internal reconnaissance and potential lateral movement.
MacOS Log Removal: endpointEndpointNoneversion:3
Detects the deletion or modification of logs on MacOS systems by identifying execution of the rm command with command-line arguments referencing system.log or audit-related paths.
Adversaries may remove or alter log files to cover their tracks and hinder detection and forensic analysis. This behavior commonly occurs during post-exploitation cleanup.
MacOS AppleScript Shell Execution and Compilation: endpointEndpointNoneversion:1
The following analytic detects the use of macOS AppleScript utilities to execute shell commands or compile AppleScript containing shell-command logic.
The analytic identifies `osascript` invocations using AppleScript's `do shell script` command, which executes shell commands on the host.
It also identifies `osacompile` invocations referencing `do shell script`. `osacompile` compiles AppleScript into a compiled script but does not execute it directly.
Adversaries may abuse these utilities to execute shell commands, stage AppleScript payloads, or prepare scripts for later execution. Matches involving `osacompile` should be interpreted as script compilation or staging rather than confirmed shell-command execution.