kevmap

TechniquesT1210 › AN0330

AN0330 Analytic 0330

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Ties inbound access to exposed services (ARD/VNC 5900, SSH 22, ScreenSharing, web services) with process crashes in unified logs and abnormal child processes spawned under those services (e.g., bash, curl) to indicate exploitation.</p>
Detects
T1210 Exploitation of Remote Services
Part of
DET0118 Exploitation of Remote Services – multi-platform lateral movement detection

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogprocess 'crashed'|'EXC_BAD_ACCESS' for sshd, screensharingd, httpd; launchd restarts of these daemons.DC0038 Application Log Content
macos:osqueryparent_name in ('sshd','httpd','screensharingd') spawning shells or scripting runtimes.DC0032 Process Creation
NSM:FlowInbound to 22/5900/8080 and follow-on internal connections.DC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ServicePortSet22, 5900, 8080/8443 by default.
AllowedAdminsMDM/jump-host IPs allowed to manage endpoints.
TimeWindowDefault: 10 minutes.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-41773Apache HTTP ServerMapped
CVE-2021-42013Apache HTTP ServerMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2024-54085AMI MegaRAC SPxMapped