kevmap

TechniquesT1132 › AN0304

AN0304 Analytic 0304

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Processes use built-in encoding utilities (e.g., base64, xxd, or plutil) to encode file contents followed by HTTP/HTTPS transfer via curl or custom applications.</p>
Detects
T1132 Data Encoding
Part of
DET0108 Detection Strategy for Data Encoding in C2 Channels

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogbase64 or curl processes chained within short execution windowDC0064 Command Execution
macos:unifiedlogHTTP POST with encoded content in user-agent or cookie fieldDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
EncodedCommandLengthThresholdMinimum byte size of encoded strings to treat as suspicious
SuspiciousProcessChainDepthNumber of chained processes within a short window to treat as a correlated behavior