Techniques › T1219 › AN1368
AN1368 Analytic 1368
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.</p>
- Detects
- T1219 Remote Access Tools
- Part of
- DET0496 Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | Process exec of remote-control apps or binaries with headless/connect flags | DC0032 Process Creation |
| macos:osquery | CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations | DC0039 File Creation |
| macos:osquery | CONNECT: Long-lived connections from remote-control parents to external IPs/domains | DC0082 Network Connection Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AllowedAppBundlePaths | Legitimate remote-support apps under /Applications. |
LaunchdAllowlist | Known-good LaunchAgents/Daemons identifiers. |
TimeWindow | Window for correlating exec→launchd→egress events. |
EgressHeuristics | Duration/volume thresholds for persistent sessions. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2018-4878 | Adobe Flash Player | Mapped |