Detection rules › Elastic
Unsigned or Untrusted Application Launch via XPC
Detects when the xpcproxy process starts an application within the /Applications directory, and the parent process is /sbin/launchd. If an application is being launched via xpcproxy with launchd as its parent process, it generally means the application is being started as an XPC service. An application being executed in this specific manner is not normal and based on testing can indicate a malicious application being launched.
MITRE ATT&CK coverage
Rule body
[rule]
description = """
Detects when the xpcproxy process starts an application within the /Applications directory, and the parent process is
/sbin/launchd. If an application is being launched via xpcproxy with launchd as its parent process, it generally means
the application is being started as an XPC service. An application being executed in this specific manner is not normal
and based on testing can indicate a malicious application being launched.
"""
id = "88d5495f-f1fa-4137-bc5d-e96abd7d199b"
license = "Elastic License v2"
name = "Unsigned or Untrusted Application Launch via XPC"
os_list = ["macos"]
reference = [
"https://attack.mitre.org/techniques/T1559/003/",
"https://attack.mitre.org/techniques/T1059/004/",
"https://medium.com/dwarves-foundation/xpc-services-on-macos-app-using-swift-657922d425cd",
]
version = "1.0.16"
query = '''
process where event.type == "start" and
process.executable like "/Applications/*" and
process.args like "xpcproxy" and
process.args like~ "application.com.*" and
process.parent.executable like "/sbin/launchd" and
(process.code_signature.trusted == false or process.code_signature.exists == false)
'''
min_endpoint_version = "8.3.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.004"
name = "Unix Shell"
reference = "https://attack.mitre.org/techniques/T1059/004/"
[[threat.technique]]
id = "T1559"
name = "Inter-Process Communication"
reference = "https://attack.mitre.org/techniques/T1559/"
[[threat.technique.subtechnique]]
id = "T1559.003"
name = "XPC Services"
reference = "https://attack.mitre.org/techniques/T1559/003/"
[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[internal]
min_endpoint_version = "8.3.0"
Stages and Predicates
Stage 1: process
process where event.type == "start" and
process.executable like "/Applications/*" and
process.args like "xpcproxy" and
process.args like~ "application.com.*" and
process.parent.executable like "/sbin/launchd" and
(process.code_signature.trusted == false or process.code_signature.exists == false)
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
event.type | eq |
| field:"event.type" kind:eq value:"start" |
process.args | wildcard |
| field:"process.args" kind:wildcard |
process.code_signature.exists | eq |
| field:"process.code_signature.exists" kind:eq value:"false" |
process.code_signature.trusted | eq |
| field:"process.code_signature.trusted" kind:eq value:"false" |
process.executable | wildcard |
| field:"Image" kind:wildcard value:"/Applications/*" |
process.parent.executable | wildcard |
| field:"ParentImage" kind:wildcard value:"/sbin/launchd" |