kevmap

TechniquesT1565 › AN0164

AN0164 Analytic 0164

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detect manipulation of system or application files in /Library, /System, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.</p>
Detects
T1565 Data Manipulation
Part of
DET0059 Detection Strategy for Data Manipulation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogAnomalous plist modifications or sensitive file overwrites by non-standard processesDC0061 File Modification
macos:osqueryopen, execve: Unexpected processes accessing or modifying critical filesDC0021 OS API Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AllowedPlistEditorsWhitelisted processes authorized to modify plist or configuration files.
FileIntegrityBaselineBaseline hash values for key files to support integrity validation.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-31207Microsoft Exchange ServerMapped
CVE-2025-24993Microsoft WindowsMapped