Search and filter across all detection sources
400 rules
Grouping macos sshd rules.
MacOS Keyboard Events
A Key Logger has potentially been detected on a macOS system
macOS Malware Detected with osquery
Malware has potentially been detected on a macOS system
Screen Capture - macOS
Detects attempts to use screencapture to collect macOS screenshots
MAL_3CXDesktopApp_MacOS_Backdoor_Mar23 [yara]
Detects 3CXDesktopApp MacOS Backdoor component
MAL_3CXDesktopApp_MacOS_UpdateAgent_Mar23 [yara]
Detects 3CXDesktopApp MacOS UpdateAgent backdoor component
Atomic MacOS Stealer - Persistence Indicators
Detects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.
CrowdStrike MacOS Added Trusted Cert
Detects attempt to install a root certificate on MacOS
MacOS Scripting Interpreter AppleScript
Detects execution of AppleScript of the macOS scripting language AppleScript.
Persistence_Agent_MacOS [yara]
Detects a Python agent that establishes persistence on macOS
SUSP_MacOS_Plist_Suspicious [yara]
Suspicious PLIST files in MacOS (possible malware persistence)
MAL_RANSOM_LNX_macOS_LockBit_Apr23_1 [yara]
Detects LockBit ransomware samples for Linux and macOS
Suspicious Execution via macOS Script Editor
Detects when the macOS Script Editor utility spawns an unusual child process.
mitre_attack_T1543_001_macos_launch_agent
Adding a plist file to macOS LaunchAgents for automatic execution on startup
mitre_attack_T1543_004_macos_launch_daemon
Adding a plist file to macOS LaunchDaemons for automatic execution on startup
APT_MAL_NK_3CX_macOS_Elextron_App_Mar23_1 [yara]
Detects macOS malware used in the 3CX incident
mitre_attack_T1564_001_macos_hidden_files_and_directories
Manually setting a file or a directory to be hidden on macOS
OSQuery Reports Application Firewall Disabled
Verifies that MacOS has automatic software updates enabled.
APT_MAL_macOS_NK_3CX_Malicious_Samples_Mar23_1 [yara]
Detects malicious macOS application related to 3CX compromise (decrypted payload)
Unsupported macOS version
Check that all laptops on the corporate environment are on a version of MacOS supported by IT.
EXPL_HKTL_macOS_Switcharoo_CVE_2022_46689_Dec22 [yara]
Detects POCs that exploit privilege escalation vulnerability CVE-2022-46689 on macOS
osquery: $(osquery.pack) $(osquery.subquery): MacOSInstallCore Chrome extension malware detected
Suspicious MacOS Firmware Activity
Detects when a user manipulates with Firmward Password on MacOS. NOTE - this command has been disabled on silicon-based apple computers.
APT_Backdoor_MacOS_GORAT_1 [yara]
This rule is looking for specific strings associated with network activity found within the MacOS generated variant of GORAT
OSX_backdoor_Bella [yara]
Bella MacOS/OSX backdoor