kevmap

TechniquesT1071.002 › AN1171

AN1171 Analytic 1171

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects Automator, AppleScript, or Terminal executing curl, lftp, or TFTP for binary transfer to untrusted IPs or unusual ports.</p>
Detects
T1071.002 File Transfer Protocols
Part of
DET0416 Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:osquerysocket_eventsDC0078 Network Traffic Flow
macos:unifiedloglog stream --predicateDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
FilePathAccessede.g., ~/Documents, ~/Library/logs/
NetworkPortAnomalyNon-standard FTP/TFTP ports used (e.g., FTP over 443)

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-40044Progress WS_FTP ServerMapped