Techniques › T1005 › AN1072
AN1072 Analytic 1072
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.</p>
- Detects
- T1005 Data from Local System
- Part of
- DET0380 Detection of Local Data Collection Prior to Exfiltration
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | process:spawn | DC0032 Process Creation |
| fs:fsusage | read/write | DC0055 File Access |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
UserContext | Useful for excluding known admin or scheduled jobs. |
TargetVolume | Focus monitoring on removable drives or external paths. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2013-0629 | Adobe ColdFusion | Mapped |
| CVE-2017-11292 | Adobe Flash Player | Mapped |
| CVE-2017-5638 | Apache Struts | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |
| CVE-2020-5902 | F5 BIG-IP | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | Mapped |
| CVE-2021-27101 | Accellion FTA | Mapped |
| CVE-2021-27102 | Accellion FTA | Mapped |
| CVE-2021-27103 | Accellion FTA | Mapped |
| CVE-2021-27104 | Accellion FTA | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | Mapped |
| CVE-2023-36884 | Microsoft Windows | Stale |
| CVE-2023-38831 | RARLAB WinRAR | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2024-38475 | Apache HTTP Server | Mapped |
| CVE-2024-41713 | Mitel MiCollab | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | Mapped |
| CVE-2024-50302 | Linux Kernel | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-53150 | Linux Kernel | Mapped |
| CVE-2024-55550 | Mitel MiCollab | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | Mapped |
| CVE-2025-21418 | Microsoft Windows | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | Mapped |
| CVE-2025-24991 | Microsoft Windows | Mapped |
| CVE-2025-43200 | Apple Multiple Products | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | Mapped |