anvilogic
low
spl
Password Validation Check via DSCL from Uncommon Process - macOS [splunk-edr]
Threat actors targeting macOS systems, such as those using Atomic Stealer, may abuse the dscl command with the authonly option to silently test for valid local credentials. This technique enables actors to verify password correctness without logging in, aiding credential validation, privilege escalation, or account enumeration. This use case detects instances where dscl authonly is executed from shell or AppleScript-based processes, indicating potential misuse of macOS directory services for cre