elastic-protections
high
eql
Initial Access via macOS Installer Package
Identifies when a macOS installer package is executed followed by the execution of a utility that's commonly used by attackers when downloading a payload, establishing persistence, profiling an endpoint, or decompressing/decoding a file before execution. An attacker may configure an installer package to download an additional payload or malware for execution to gain initial access or establish persistence on an endpoint.