kevmap

TechniquesT1486 › AN0604

AN0604 Analytic 0604

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using srm, gpg, or compiled payloads. Often correlated with ransom note creation in multiple directories.</p>
Detects
T1486 Data Encrypted for Impact
Part of
DET0215 Detection of Multi-Platform File Encryption for Impact

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogfile encrypted|new file with .encrypted extension|disk write burstDC0061 File Modification
macos:unifiedlogexec srm|exec openssl|exec gpgDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ExtensionPatternEncrypted files may use .locked, .enc, or ransom-specific extensions.
VolumeTargetedDetect activity targeting mounted external or backup volumes.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped