Techniques › T1212 › AN0495
AN0495 Analytic 0495
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.</p>
- Detects
- T1212 Exploitation for Credential Access
- Part of
- DET0174 Detection Strategy for Exploitation for Credential Access
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | opendirectoryd crashes or abnormal authentication errors | DC0038 Application Log Content |
| macos:osquery | execve: Processes unexpectedly invoking Keychain or authentication APIs | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
WatchedAPIs | List of authentication and Keychain-related APIs to monitor for unauthorized access. |
CrashCorrelationWindow | Time window for correlating authentication service crashes with subsequent suspicious access. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2022-22948 | VMware vCenter Server | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | Mapped |