kevmap

TechniquesT1027.009 › AN0601

AN0601 Analytic 0601

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of Mach-O binaries or AppleScripts that contain nested, encoded, or run-only embedded payloads dropped at runtime.</p>
Detects
T1027.009 Embedded Payloads
Part of
DET0214 Detection Strategy for Embedded Payloads

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedloglogd:file writeDC0039 File Creation
macos:endpointsecurityES_EVENT_TYPE_NOTIFY_EXECDC0032 Process Creation
macos:osquerymach_o_info, file_metadataDC0059 File Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ScriptFormatTypeRun-only AppleScripts or signed scripting payloads may require scoped detection
DroppedBinaryCountThreshold on number of binaries created by the parent payload
ParentProcessNameAllows focusing on suspicious interpreter or staging tools