{"id":"T1546.014","name":"Emond","url":"https://attack.mitre.org/techniques/T1546/014","tactics":["privilege-escalation","persistence"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0555","stix_id":"x-mitre-detection-strategy--f0ef3932-5f60-4dfc-9725-8639d67349cc","name":"Detection Strategy for Event Triggered Execution via emond on macOS","url":"https://attack.mitre.org/detectionstrategies/DET0555","analytics":[{"id":"AN1534","stix_id":"x-mitre-analytic--5e4aea30-f04b-4f1e-b68a-f2f3a95e5066","name":"Analytic 1534","description":"Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.","url":"https://attack.mitre.org/detectionstrategies/DET0555#AN1534","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"file create or modify in /etc/emond.d/rules or /private/var/db/emondClients","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"execution of /sbin/emond with child processes launched","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"rule definitions written to emond rule plists","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"command execution triggered by emond (e.g., shell, curl, python)","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PathPrefix","description":"Paths such as `/etc/emond.d/rules/` and `/private/var/db/emondClients` may vary slightly or be symlinked in some setups"},{"field":"TimeWindow","description":"The time range for correlating rule file creation to emond execution may be tuned based on system performance and usage"},{"field":"ParentProcessFilter","description":"Defenders may wish to restrict alerts to emond processes not spawned from trusted system update or provisioning tools"},{"field":"CommandPatternList","description":"List of known suspicious commands or binaries used by adversaries (e.g., reverse shells, persistence scripts)"}],"live":true,"detection_strategies":["DET0555"],"techniques":["T1546.014"]}],"live":true,"version":"1.0","techniques":["T1546.014"]}],"sigma_rules":[{"id":"23c43900-e732-45a4-8354-63e4a6c187ce","title":"MacOS Emond Launch Daemon","author":"Alejandro Ortuno, oscd.community","status":"test","level":"medium","date":"2020-10-23","modified":"2021-11-27","description":"Detects additions to the Emond Launch Daemon that adversaries may use to gain persistence and elevate privileges.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.014/T1546.014.md","https://posts.specterops.io/leveraging-emond-on-macos-for-persistence-a040a2785124"],"logsource":{"product":"macos","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.014"],"path":"rules/macos/file_event/file_event_macos_emond_launch_daemon.yml","techniques":["T1546.014"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}