kevmap

TechniquesT1036.005 › AN0985

AN0985 Analytic 0985

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin.</p>
Detects
T1036.005 Match Legitimate Resource Name or Location
Part of
DET0347 Detection Strategy for Masquerading via Legitimate Resource Name or Location

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedloglog collect from launchd and process startDC0034 Process Metadata
fs:fsusagefilesystem monitoring of exec/openDC0059 File Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
expected_bundle_namesList of known application names and paths to validate against
signed_by_apple_checkToggle to enforce checks for Apple-signed binaries in trusted directories

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-26360Adobe ColdFusionMapped