macOS coverage

405 of 625 macOS detection rules across 4 vendors map to a specific Endpoint Security event; the remaining 220 are grouped by MITRE technique.

Attributed to an ESF event

405 rules that resolve to a specific Endpoint Security event type, grouped by Apple's functional-domain section.

File System Events

File Open 33 rules
File or Directory Create 10 rules
File Rename 6 rules
File Write 54 rules

Process Events

Process Execution 322 rules
Process Fork 7 rules
Signal Delivery 3 rules

Kernel Events

Kernel Extension Load 3 rules
Kernel Extension Unload 3 rules

XPC Events

XPC Service Connection 3 rules

Authentication Events

sudo Command Execution 1 rule

TCC Events

TCC Privacy Permission Modified 1 rule

Not attributed to an ESF event

220 rules that target macOS but resolve to no specific Endpoint Security event (generic process / command-line fields with no ESF event signal), grouped by the MITRE technique they detect.

Resource Development

T1587.001 Develop Capabilities: Malware 1 rule
T1588 Obtain Capabilities 1 rule

Initial Access

T1078 Valid Accounts 1 rule
T1078.004 Valid Accounts: Cloud Accounts 1 rule
T1091 Replication Through Removable Media 1 rule
T1133 External Remote Services 3 rules
T1189 Drive-by Compromise 1 rule
T1190 Exploit Public-Facing Application 2 rules
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools 2 rules
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain 1 rule

Execution

T1053.002 Scheduled Task/Job: At 1 rule
T1053.003 Scheduled Task/Job: Cron 2 rules
T1059 Command and Scripting Interpreter 5 rules
T1059.001 Command and Scripting Interpreter: PowerShell 8 rules
T1059.002 Command and Scripting Interpreter: AppleScript 11 rules
T1059.003 Command and Scripting Interpreter: Windows Command Shell 2 rules
T1059.004 Command and Scripting Interpreter: Unix Shell 19 rules
T1059.006 Command and Scripting Interpreter: Python 12 rules
T1059.007 Command and Scripting Interpreter: JavaScript 7 rules
T1106 Native API 3 rules
T1129 Shared Modules 2 rules
T1203 Exploitation for Client Execution 2 rules
T1204 User Execution 3 rules
T1204.001 User Execution: Malicious Link 1 rule
T1204.002 User Execution: Malicious File 4 rules
T1559 Inter-Process Communication 2 rules
T1559.003 Inter-Process Communication: XPC Services 2 rules
T1569.001 System Services: Launchctl 1 rule

Persistence

(no specific technique) 1 rule
T1037 Boot or Logon Initialization Scripts 1 rule
T1037.002 Boot or Logon Initialization Scripts: Login Hook 3 rules
T1037.005 Boot or Logon Initialization Scripts: Startup Items 1 rule
T1053.002 Scheduled Task/Job: At 1 rule
T1053.003 Scheduled Task/Job: Cron 2 rules
T1078.003 Valid Accounts: Local Accounts 2 rules
T1098 Account Manipulation 1 rule
T1098.004 Account Manipulation: SSH Authorized Keys 1 rule
T1133 External Remote Services 1 rule
T1136 Create Account 1 rule
T1136.001 Create Account: Local Account 2 rules
T1176 Software Extensions 1 rule
T1543 Create or Modify System Process 3 rules
T1543.001 Create or Modify System Process: Launch Agent 9 rules
T1543.004 Create or Modify System Process: Launch Daemon 6 rules
T1546 Event Triggered Execution 3 rules
T1546.002 Event Triggered Execution: Screensaver 1 rule
T1546.004 Event Triggered Execution: Unix Shell Configuration Modification 1 rule
T1546.014 Event Triggered Execution: Emond 2 rules
T1546.016 Event Triggered Execution: Installer Packages 3 rules
T1547 Boot or Logon Autostart Execution 7 rules
T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions 2 rules
T1547.015 Boot or Logon Autostart Execution: Login Items 1 rule
T1556 Modify Authentication Process 1 rule

Privilege Escalation

T1037.002 Boot or Logon Initialization Scripts: Login Hook 1 rule
T1053.003 Scheduled Task/Job: Cron 1 rule
T1055 Process Injection 1 rule
T1068 Exploitation for Privilege Escalation 3 rules
T1078 Valid Accounts 3 rules
T1078.003 Valid Accounts: Local Accounts 3 rules
T1098.007 Account Manipulation: Additional Local or Domain Groups 2 rules
T1484 Domain or Tenant Policy Modification 1 rule
T1543 Create or Modify System Process 1 rule
T1546.014 Event Triggered Execution: Emond 1 rule
T1548 Abuse Elevation Control Mechanism 3 rules
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid 1 rule
T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching 4 rules
T1548.004 Abuse Elevation Control Mechanism: Elevated Execution with Prompt 2 rules
T1548.006 Abuse Elevation Control Mechanism: TCC Manipulation 4 rules

Stealth

(no specific technique) 1 rule
T1006 Direct Volume Access 1 rule
T1027 Obfuscated Files or Information 3 rules
T1027.004 Obfuscated Files or Information: Compile After Delivery 1 rule
T1027.010 Obfuscated Files or Information: Command Obfuscation 1 rule
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File 1 rule
T1027.015 Obfuscated Files or Information: Compression 1 rule
T1036.005 Masquerading: Match Legitimate Resource Name or Location 1 rule
T1036.006 Masquerading: Space after Filename 1 rule
T1055 Process Injection 1 rule
T1070 Indicator Removal 1 rule
T1070.004 Indicator Removal: File Deletion 3 rules
T1078.003 Valid Accounts: Local Accounts 1 rule
T1140 Deobfuscate/Decode Files or Information 5 rules
T1211 Exploitation for Stealth 1 rule
T1218.011 System Binary Proxy Execution: Rundll32 1 rule
T1497.001 Virtualization/Sandbox Evasion: System Checks 1 rule
T1564.001 Hide Artifacts: Hidden Files and Directories 8 rules
T1564.002 Hide Artifacts: Hidden Users 1 rule
T1564.003 Hide Artifacts: Hidden Window 1 rule
T1574 Hijack Execution Flow 2 rules
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking 1 rule
T1574.007 Hijack Execution Flow: Path Interception by PATH Environment Variable 1 rule
T1620 Reflective Code Loading 3 rules

Defense Impairment

T1222 File and Directory Permissions Modification 2 rules
T1484 Domain or Tenant Policy Modification 1 rule
T1553 Subvert Trust Controls 1 rule
T1553.001 Subvert Trust Controls: Gatekeeper Bypass 7 rules
T1553.002 Subvert Trust Controls: Code Signing 1 rule
T1553.004 Subvert Trust Controls: Install Root Certificate 1 rule
T1647 Plist File Modification 11 rules
T1685 Disable or Modify Tools 18 rules
T1686 Disable or Modify System Firewall 1 rule

Credential Access

T1003 OS Credential Dumping 4 rules
T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow 1 rule
T1110 Brute Force 2 rules
T1528 Steal Application Access Token 1 rule
T1539 Steal Web Session Cookie 1 rule
T1552.001 Unsecured Credentials: Credentials In Files 5 rules
T1552.005 Unsecured Credentials: Cloud Instance Metadata API 2 rules
T1555 Credentials from Password Stores 3 rules
T1555.001 Credentials from Password Stores: Keychain 4 rules
T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting 3 rules
T1558.005 Steal or Forge Kerberos Tickets: Ccache Files 2 rules

Discovery

(no specific technique) 1 rule
T1016 System Network Configuration Discovery 2 rules
T1016.001 System Network Configuration Discovery: Internet Connection Discovery 1 rule
T1046 Network Service Discovery 1 rule
T1069.001 Permission Groups Discovery: Local Groups 1 rule
T1069.002 Permission Groups Discovery: Domain Groups 1 rule
T1082 System Information Discovery 2 rules
T1083 File and Directory Discovery 1 rule
T1087.001 Account Discovery: Local Account 1 rule
T1087.002 Account Discovery: Domain Account 1 rule
T1135 Network Share Discovery 1 rule
T1497.001 Virtualization/Sandbox Evasion: System Checks 1 rule
T1518.001 Software Discovery: Security Software Discovery 1 rule
T1580 Cloud Infrastructure Discovery 1 rule

Lateral Movement

T1021 Remote Services 2 rules
T1021.002 Remote Services: SMB/Windows Admin Shares 2 rules
T1021.004 Remote Services: SSH 4 rules
T1021.005 Remote Services: VNC 1 rule
T1091 Replication Through Removable Media 1 rule
T1550.002 Use Alternate Authentication Material: Pass the Hash 1 rule
T1550.003 Use Alternate Authentication Material: Pass the Ticket 2 rules
T1563 Remote Service Session Hijacking 2 rules
T1563.001 Remote Service Session Hijacking: SSH Hijacking 1 rule
T1570 Lateral Tool Transfer 1 rule

Collection

T1005 Data from Local System 7 rules
T1039 Data from Network Shared Drive 1 rule
T1056 Input Capture 1 rule
T1074.001 Data Staged: Local Data Staging 1 rule
T1213.003 Data from Information Repositories: Code Repositories 1 rule
T1560.001 Archive Collected Data: Archive via Utility 3 rules
T1560.002 Archive Collected Data: Archive via Library 1 rule

Command & Control

(no specific technique) 1 rule
T1071 Application Layer Protocol 5 rules
T1071.001 Application Layer Protocol: Web Protocols 8 rules
T1071.004 Application Layer Protocol: DNS 3 rules
T1090 Proxy 3 rules
T1095 Non-Application Layer Protocol 1 rule
T1102 Web Service 3 rules
T1102.001 Web Service: Dead Drop Resolver 1 rule
T1102.002 Web Service: Bidirectional Communication 4 rules
T1105 Ingress Tool Transfer 15 rules
T1132.001 Data Encoding: Standard Encoding 1 rule
T1219 Remote Access Tools 2 rules
T1568 Dynamic Resolution 1 rule
T1568.002 Dynamic Resolution: Domain Generation Algorithms 1 rule
T1571 Non-Standard Port 1 rule
T1572 Protocol Tunneling 2 rules

Exfiltration

T1030 Data Transfer Size Limits 2 rules
T1041 Exfiltration Over C2 Channel 1 rule
T1048 Exfiltration Over Alternative Protocol 2 rules
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB 1 rule
T1537 Transfer Data to Cloud Account 1 rule
T1567 Exfiltration Over Web Service 1 rule
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage 3 rules
T1567.003 Exfiltration Over Web Service: Exfiltration to Text Storage Sites 1 rule
T1567.004 Exfiltration Over Web Service: Exfiltration Over Webhook 1 rule

Impact

T1485 Data Destruction 1 rule
T1486 Data Encrypted for Impact 1 rule
T1489 Service Stop 2 rules
T1529 System Shutdown/Reboot 1 rule
T1565.001 Data Manipulation: Stored Data Manipulation 2 rules

(no MITRE mapping)

(no MITRE mapping) 7 rules