kevmap

TechniquesT1219 › AN1368

AN1368 Analytic 1368

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.</p>
Detects
T1219 Remote Access Tools
Part of
DET0496 Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogProcess exec of remote-control apps or binaries with headless/connect flagsDC0032 Process Creation
macos:osqueryCREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locationsDC0039 File Creation
macos:osqueryCONNECT: Long-lived connections from remote-control parents to external IPs/domainsDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AllowedAppBundlePathsLegitimate remote-support apps under /Applications.
LaunchdAllowlistKnown-good LaunchAgents/Daemons identifiers.
TimeWindowWindow for correlating exec→launchd→egress events.
EgressHeuristicsDuration/volume thresholds for persistent sessions.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2018-4878Adobe Flash PlayerMapped