Browse Rules

Search and filter across all detection sources

400 rules

wazuh informational xml

Grouping macos sshd rules.

Grouping macos sshd rules.

panther medium python

MacOS Keyboard Events

A Key Logger has potentially been detected on a macOS system

panther medium python

macOS Malware Detected with osquery

Malware has potentially been detected on a macOS system

sigma low sigma

Screen Capture - macOS

Detects attempts to use screencapture to collect macOS screenshots

signature-base unknown yara

MAL_3CXDesktopApp_MacOS_Backdoor_Mar23 [yara]

Detects 3CXDesktopApp MacOS Backdoor component

signature-base unknown yara

MAL_3CXDesktopApp_MacOS_UpdateAgent_Mar23 [yara]

Detects 3CXDesktopApp MacOS UpdateAgent backdoor component

sigma high sigma

Atomic MacOS Stealer - Persistence Indicators

Detects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.

panther medium python

CrowdStrike MacOS Added Trusted Cert

Detects attempt to install a root certificate on MacOS

sigma medium sigma

MacOS Scripting Interpreter AppleScript

Detects execution of AppleScript of the macOS scripting language AppleScript.

signature-base unknown yara

Persistence_Agent_MacOS [yara]

Detects a Python agent that establishes persistence on macOS

signature-base unknown yara

SUSP_MacOS_Plist_Suspicious [yara]

Suspicious PLIST files in MacOS (possible malware persistence)

signature-base unknown yara

MAL_RANSOM_LNX_macOS_LockBit_Apr23_1 [yara]

Detects LockBit ransomware samples for Linux and macOS

sigma medium sigma

Suspicious Execution via macOS Script Editor

Detects when the macOS Script Editor utility spawns an unusual child process.

chronicle unknown yara-l

mitre_attack_T1543_001_macos_launch_agent

Adding a plist file to macOS LaunchAgents for automatic execution on startup

chronicle unknown yara-l

mitre_attack_T1543_004_macos_launch_daemon

Adding a plist file to macOS LaunchDaemons for automatic execution on startup

signature-base unknown yara

APT_MAL_NK_3CX_macOS_Elextron_App_Mar23_1 [yara]

Detects macOS malware used in the 3CX incident

chronicle unknown yara-l

mitre_attack_T1564_001_macos_hidden_files_and_directories

Manually setting a file or a directory to be hidden on macOS

panther medium python

OSQuery Reports Application Firewall Disabled

Verifies that MacOS has automatic software updates enabled.

signature-base unknown yara

APT_MAL_macOS_NK_3CX_Malicious_Samples_Mar23_1 [yara]

Detects malicious macOS application related to 3CX compromise (decrypted payload)

panther low python

Unsupported macOS version

Check that all laptops on the corporate environment are on a version of MacOS supported by IT.

signature-base unknown yara

EXPL_HKTL_macOS_Switcharoo_CVE_2022_46689_Dec22 [yara]

Detects POCs that exploit privilege escalation vulnerability CVE-2022-46689 on macOS

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): MacOSInstallCore Chrome extension malware detected

osquery: $(osquery.pack) $(osquery.subquery): MacOSInstallCore Chrome extension malware detected

sigma medium sigma

Suspicious MacOS Firmware Activity

Detects when a user manipulates with Firmward Password on MacOS. NOTE - this command has been disabled on silicon-based apple computers.

signature-base unknown yara

APT_Backdoor_MacOS_GORAT_1 [yara]

This rule is looking for specific strings associated with network activity found within the MacOS generated variant of GORAT

signature-base unknown yara

OSX_backdoor_Bella [yara]

Bella MacOS/OSX backdoor