Plist File Modification T1647
Tactic: Defense Impairment
Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses. macOS applications use plist files, such as the info.plist file, to store properties and configuration settings that inform the operating system how to handle the application at runtime. Plist files are structured metadata in key-value pairs formatted in XML based on Apple's Core Foundation DTD. Plist files can be saved in text or binary format.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| ESF | fork | Process Fork |
| ESF | write | File Write |
Authoring guide
These 14 rules share fields, values, and exclusions.
Fields filtered most (21 distinct)
These fields appear most often in rule filters.
Top indicator values (128 distinct)
These values appear most often in rule predicates.
Exclusions (107 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint
Elastic 12 rules
- Creation of Hidden Login Item via Apple Script
- Initial Access or Execution via Microsoft Office Application
- Initial Access via macOS Installer Package
- Modification of Safari Settings via Defaults Command
- Persistence via a Hidden Plist Filename
- Persistence via a Masqueraded Plist Filename
- Persistence via Suspicious Launch Agent or Launch Daemon
- Potential Persistence via Login Hook
- SoftwareUpdate Preferences Modification
- Suspicious Apple Mail Rule Plist Modification
- Suspicious Dock Plist Configuration Modification
- Unusual Launch Service Creation via Unsigned or Untrusted Binary