{"id":"T1555.002","name":"Securityd Memory","url":"https://attack.mitre.org/techniques/T1555/002","tactics":["credential-access"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0057","stix_id":"x-mitre-detection-strategy--f07cfa67-8a83-4a62-ae18-bee29bfc7569","name":"Detect Suspicious Access to securityd Memory for Credential Extraction","url":"https://attack.mitre.org/detectionstrategies/DET0057","analytics":[{"id":"AN0156","stix_id":"x-mitre-analytic--94628b16-2443-4e66-9f7b-a61a39012a9c","name":"Analytic 0156","description":"Detects suspicious memory access attempts targeting the `securityd` process. Observes tools invoking process memory read operations (e.g., ptrace, task_for_pid) against `securityd`. Correlates with anomalous parent process lineage, root privilege escalation, or repeated unauthorized attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0057#AN0156","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"ptrace or task_for_pid","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"execution of memory inspection tools (lldb, gdb, osqueryi)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AllowedDebuggers","description":"List of authorized debugging tools permitted in dev/test environments"},{"field":"TimeWindow","description":"Correlation period between memory inspection and Keychain API access"},{"field":"PrivilegedUsers","description":"Expected set of admin accounts with legitimate debugging permissions"}],"live":true,"detection_strategies":["DET0057"],"techniques":["T1555.002"]},{"id":"AN0157","stix_id":"x-mitre-analytic--9e0af3ac-dfeb-48c3-8d15-5f9edd69be69","name":"Analytic 0157","description":"Detects adversaries attempting to attach debuggers or memory dump utilities to credential storage daemons analogous to macOS `securityd`. Observes ptrace syscalls, /proc/<pid>/mem access, or gcore dumps against sensitive processes. Correlates anomalies with privilege escalation or credential dumping attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0057#AN0157","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"ptrace attach","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"auditd-syscall"},{"name":"auditd:FILE","channel":"/proc/*/mem read attempt","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-file"},{"name":"auditd:EXECVE","channel":"gcore, gdb, strings, hexdump execution","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"MonitoredProcesses","description":"List of credential storage daemons (e.g., securityd, gnome-keyring, kwallet) monitored for memory access attempts"},{"field":"CorrelationDepth","description":"Defines how many chained events (process execution + syscall + file read) to correlate before raising an alert"},{"field":"PrivilegeContext","description":"Expected user/group context for processes allowed to access protected memory"}],"live":true,"detection_strategies":["DET0057"],"techniques":["T1555.002"]}],"live":true,"version":"1.0","techniques":["T1555.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}