{"id":"T1547.007","name":"Re-opened Applications","url":"https://attack.mitre.org/techniques/T1547/007","tactics":["persistence","privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0125","stix_id":"x-mitre-detection-strategy--5ac0e527-2ebd-44a1-8d87-4de8463b761c","name":"Detect persistence via reopened application plist modification (macOS)","url":"https://attack.mitre.org/detectionstrategies/DET0125","analytics":[{"id":"AN0349","stix_id":"x-mitre-analytic--67d1900f-9e02-4290-a14c-6d32be508d19","name":"Analytic 0349","description":"Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login.","url":"https://attack.mitre.org/detectionstrategies/DET0125#AN0349","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of process launched via loginwindow session restore","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:filesystem","channel":"Modification or creation of files matching 'com.apple.loginwindow.*.plist' in ~/Library/Preferences/ByHost","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-filesystem"},{"name":"macos:unifiedlog","channel":"LoginWindow context with associated PID linked to reopened plist paths","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"es_event_file_rename_t or es_event_file_write_t","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"UserContext","description":"Restrict to targeted users or unexpected users writing to plist"},{"field":"FilePathPattern","description":"Allow tuning for alternative persistence paths or directory redirection"},{"field":"TimeWindow","description":"Correlate plist write and process execution within logon window"},{"field":"BinaryAnomalyScore","description":"Optional scoring of launched binary based on code signing, entropy, and known safe apps"}],"live":true,"detection_strategies":["DET0125"],"techniques":["T1547.007"]}],"live":true,"version":"1.0","techniques":["T1547.007"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}