Techniques › T1565 › AN0164
AN0164 Analytic 0164
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detect manipulation of system or application files in
/Library, /System, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.</p>- Detects
- T1565 Data Manipulation
- Part of
- DET0059 Detection Strategy for Data Manipulation
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | Anomalous plist modifications or sensitive file overwrites by non-standard processes | DC0061 File Modification |
| macos:osquery | open, execve: Unexpected processes accessing or modifying critical files | DC0021 OS API Execution |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AllowedPlistEditors | Whitelisted processes authorized to modify plist or configuration files. |
FileIntegrityBaseline | Baseline hash values for key files to support integrity validation. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2021-31207 | Microsoft Exchange Server | Mapped |
| CVE-2025-24993 | Microsoft Windows | Mapped |