kevmap

TechniquesT1203 › AN0799

AN0799 Analytic 0799

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.</p>
Detects
T1203 Exploitation for Client Execution
Part of
DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogprocess crash, abort, code signing violationsDC0038 Application Log Content
fs:fseventscreate/write/rename under user-writable pathsDC0061 File Modification
macos:osqueryexecDC0032 Process Creation
NSM:Connectionsnew connections from exploited lineageDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindow10–30m correlation window.
HighRiskChildrenosascript, bash, zsh, curl, python, pbpaste/pbcopy, open -a Terminal.
UserPaths~/Library/LaunchAgents, ~/Library/Containers/*/Data, /private/var/folders/*.
QuarantineBypassFlag files with missing com.apple.quarantine extended attribute when sourced from internet.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2021-21148Google Chromium V8Mapped
CVE-2021-21166Google ChromiumMapped
CVE-2021-21206Google Chromium BlinkMapped
CVE-2021-27059Microsoft OfficeMapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU)Mapped
CVE-2021-30554Google Chromium WebGLMapped
CVE-2021-37975Google Chromium V8Mapped
CVE-2021-39144XStream XStreamMapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-23748Audinate Dante DiscoveryMapped
CVE-2022-41128Microsoft WindowsMapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2023-21608Adobe Acrobat and ReaderMapped
CVE-2023-23397Microsoft OfficeMapped
CVE-2023-26369Adobe Acrobat and ReaderMapped
CVE-2023-34048VMware vCenter ServerMapped
CVE-2023-36844Juniper Junos OSMapped
CVE-2023-47565QNAP VioStor NVRMapped
CVE-2023-49897FXC AE1021, AE1021PEMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-26169Microsoft WindowsMapped
CVE-2024-45195Apache OFBizMapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-24993Microsoft WindowsMapped
CVE-2025-27038Qualcomm Multiple ChipsetsMapped
CVE-2025-2783Google Chromium MojoMapped
CVE-2025-30397Microsoft WindowsMapped
CVE-2025-30406Gladinet CentreStackMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale
CVE-2025-3248Langflow LangflowMapped
CVE-2025-3935ConnectWise ScreenConnectMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-43200Apple Multiple ProductsMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6543Citrix NetScaler ADC and GatewayMapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped