kevmap

TechniquesT1205 › AN1450

AN1450 Analytic 1450

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment.</p>
Detects
T1205 Traffic Signaling
Part of
DET0524 Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogexec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumersDC0032 Process Creation
macos:unifiedlogFirewall rule enable/disable or listen socket changesDC0078 Network Traffic Flow
NSM:FlowClosed-port hits followed by success from same src_ipDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
PFAnchorPathsAnchors or conf files monitored for change (/etc/pf.conf, /etc/pf.anchors/*).
DeveloperModeReduce noise on dev endpoints compiling or testing PF rules.