kevmap

TechniquesT1059 › AN1430

AN1430 Analytic 1430

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects launch of command-line interpreters via Terminal, Automator, or hidden osascript, especially when parent process lineage deviates from user-initiated applications.</p>
Detects
T1059 Command and Scripting Interpreter
Part of
DET0516 Behavioral Detection of Command and Scripting Interpreter Abuse

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedloglog stream --info --predicate 'eventMessage CONTAINS "exec"'DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
LaunchAgentNameMonitor for specific plist agents frequently abused for persistence or payload execution.
ScriptNamePath or script name pattern (e.g., hidden files, /tmp locations).
TerminalAppUsageAdjust based on whether Terminal.app use is common or restricted in user policy.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-2883Adobe Acrobat and ReaderMapped
CVE-2016-4437Apache ShiroMapped
CVE-2017-11882Microsoft OfficeMapped
CVE-2017-5638Apache StrutsMapped
CVE-2017-6742Cisco IOS and IOS XE SoftwareMapped
CVE-2017-9805Apache StrutsMapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN)Mapped
CVE-2018-11776Apache StrutsMapped
CVE-2018-6789Exim EximMapped
CVE-2018-7600Drupal Drupal CoreMapped
CVE-2019-11510Ivanti Pulse Connect SecureMapped
CVE-2019-11580Atlassian Crowd and Crowd Data CenterMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2019-17558Apache SolrMapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2019-3398Atlassian Confluence Server and Data CenterMapped
CVE-2020-0787Microsoft WindowsMapped
CVE-2020-15505Ivanti MobileIron Multiple ProductsMapped
CVE-2020-17530Apache StrutsMapped
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-29557D-Link DIR-825 R1 DevicesMapped
CVE-2020-29574Sophos CyberoamOSMapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8515DrayTek Multiple Vigor RoutersMapped
CVE-2021-1497Cisco HyperFlex HXMapped
CVE-2021-1498Cisco HyperFlex HXMapped
CVE-2021-20035SonicWall SMA100 AppliancesMapped
CVE-2021-21972VMware vCenter ServerMapped
CVE-2021-22005VMware vCenter ServerMapped
CVE-2021-22204Perl ExiftoolMapped
CVE-2021-22205GitLab Community and Enterprise EditionsMapped
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-22894Ivanti Pulse Connect SecureMapped
CVE-2021-22900Ivanti Pulse Connect SecureMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26084Atlassian Confluence Server and Data CenterMapped
CVE-2021-27101Accellion FTAMapped
CVE-2021-27102Accellion FTAMapped
CVE-2021-27104Accellion FTAMapped
CVE-2021-31166Microsoft HTTP Protocol StackMapped
CVE-2021-3129Laravel IgnitionMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-35464ForgeRock Access Management (AM)Mapped
CVE-2021-41773Apache HTTP ServerMapped
CVE-2021-42013Apache HTTP ServerMapped
CVE-2021-42237Sitecore XPMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-42321Microsoft ExchangeMapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2021-45382D-Link Multiple RoutersMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-21971Microsoft WindowsMapped
CVE-2022-21999Microsoft WindowsMapped
CVE-2022-22047Microsoft WindowsMapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2022-22965VMware Spring FrameworkMapped
CVE-2022-23131Zabbix FrontendMapped
CVE-2022-23748Audinate Dante DiscoveryMapped
CVE-2022-24521Microsoft WindowsMapped
CVE-2022-26258D-Link DIR-820LMapped
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped
CVE-2022-29303SolarView CompactMapped
CVE-2022-34713Microsoft WindowsMapped
CVE-2022-35405Zoho ManageEngineMapped
CVE-2022-35914Teclib GLPIMapped
CVE-2022-36804Atlassian Bitbucket Server and Data CenterMapped
CVE-2022-37969Microsoft WindowsMapped
CVE-2022-39197Fortra Cobalt StrikeMapped
CVE-2022-41125Microsoft WindowsMapped
CVE-2022-42948Fortra Cobalt StrikeMapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2023-20109Cisco IOS and IOS XEMapped
CVE-2023-20118Cisco Small Business RV Series RoutersMapped
CVE-2023-20273Cisco Cisco IOS XE Web UIMapped
CVE-2023-20867VMware ToolsMapped
CVE-2023-20887VMware Aria Operations for NetworksMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2023-2533PaperCut NG/MFMapped
CVE-2023-26359Adobe ColdFusionMapped
CVE-2023-27350PaperCut MF/NGMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) ApplianceMapped
CVE-2023-33246Apache RocketMQMapped
CVE-2023-33538TP-Link Multiple RoutersMapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS)Mapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-36845Juniper Junos OSMapped
CVE-2023-36846Juniper Junos OSMapped
CVE-2023-36847Juniper Junos OSMapped
CVE-2023-36851Juniper Junos OSMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2023-40044Progress WS_FTP ServerMapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business SecurityMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-48365Qlik SenseMapped
CVE-2023-48788Fortinet FortiClient EMSMapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcelMapped
CVE-2024-11182MDaemon Email ServerMapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)Mapped
CVE-2024-12987DrayTek Vigor RoutersMapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20399Cisco NX-OSMapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM)Mapped
CVE-2024-21413Microsoft Office OutlookMapped
CVE-2024-21887Ivanti Connect Secure and Policy SecureMapped
CVE-2024-26169Microsoft WindowsMapped
CVE-2024-27198JetBrains TeamCityMapped
CVE-2024-29059Microsoft .NET FrameworkMapped
CVE-2024-34102Adobe Commerce and Magento Open SourceMapped
CVE-2024-38475Apache HTTP ServerMapped
CVE-2024-41710Mitel SIP PhonesMapped
CVE-2024-45195Apache OFBizMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4761Google Chromium V8Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-4885Progress WhatsUp GoldMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-50603Aviatrix ControllersMapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-53104Linux KernelMapped
CVE-2024-53197Linux KernelMapped
CVE-2024-56145Craft CMS Craft CMSMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2024-57968Advantive VeraCoreMapped
CVE-2024-58136Yiiframework YiiMapped
CVE-2024-6047GeoVision Multiple DevicesMapped
CVE-2025-0994Trimble CityworksMapped
CVE-2025-1976Broadcom Brocade Fabric OSMapped
CVE-2025-20281Cisco Identity Services EngineMapped
CVE-2025-20337Cisco Identity Services EngineMapped
CVE-2025-21590Juniper Junos OSMapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-23006SonicWall SMA1000 AppliancesMapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-24085Apple Multiple ProductsMapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-24985Microsoft WindowsMapped
CVE-2025-27038Qualcomm Multiple ChipsetsMapped
CVE-2025-30397Microsoft WindowsMapped
CVE-2025-30406Gladinet CentreStackMapped
CVE-2025-31161CrushFTP CrushFTPMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale
CVE-2025-31324SAP NetWeaverMapped
CVE-2025-32433Erlang Erlang/OTPMapped
CVE-2025-3248Langflow LangflowMapped
CVE-2025-32701Microsoft WindowsMapped
CVE-2025-32706Microsoft WindowsMapped
CVE-2025-32709Microsoft WindowsMapped
CVE-2025-32756Fortinet Multiple ProductsMapped
CVE-2025-33053Microsoft WindowsMapped
CVE-2025-35939Craft CMS Craft CMSMapped
CVE-2025-3928Commvault Web ServerMapped
CVE-2025-3935ConnectWise ScreenConnectMapped
CVE-2025-42599Qualitia Active! MailMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4632Samsung MagicINFO 9 ServerMapped
CVE-2025-47812Wing FTP Server Wing FTP ServerMapped
CVE-2025-53770Microsoft SharePointMapped
CVE-2025-6543Citrix NetScaler ADC and GatewayMapped
CVE-2025-6554Google Chromium V8Mapped