{"id":"T1548.004","name":"Elevated Execution with Prompt","url":"https://attack.mitre.org/techniques/T1548/004","tactics":["privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0395","stix_id":"x-mitre-detection-strategy--2dd0f2ef-2c31-4b11-a507-91067bb61787","name":"macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection","url":"https://attack.mitre.org/detectionstrategies/DET0395","analytics":[{"id":"AN1111","stix_id":"x-mitre-analytic--aae53d47-1f26-426b-9e50-848f186fed99","name":"Analytic 1111","description":"Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.","url":"https://attack.mitre.org/detectionstrategies/DET0395#AN1111","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of /usr/libexec/security_authtrampoline or child processes originating from non-trusted binaries triggering credential prompts","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Calls to AuthorizationExecuteWithPrivileges() observed via Apple System Logger or security_auditing tools","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"User credential prompt events without associated trusted installer package","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"BinaryReputationList","description":"Allow list of trusted binaries invoking elevation prompts"},{"field":"TimeWindow","description":"Temporal correlation threshold between API call and credential prompt"},{"field":"PromptContextValidation","description":"Heuristic filters to determine whether a prompt context matches known legitimate installers"}],"live":true,"detection_strategies":["DET0395"],"techniques":["T1548.004"]}],"live":true,"version":"1.0","techniques":["T1548.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}