macOS SIP Status Enumeration via csrutil status
Flags execution of "csrutil status" on macOS to enumerate System Integrity Protection state.
- Product
- macos
- Category
- process_creation
- Author
- Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2024-01-02
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process executions of /csrutil with the argument indicating “status”, which enumerates the current System Integrity Protection (SIP) state. Attackers often perform this post-exploitation check to understand available security restrictions before attempting further actions. It relies on macOS process creation telemetry capturing the executable path and command-line arguments.
Reporting behind it
- ss64.comhttps://ss64.com/osx/csrutil.html
- objective-see.orghttps://objective-see.org/blog/blog_0x6D.html
- welivesecurity.comhttps://www.welivesecurity.com/2017/10/20/osx-proton-supply-chain-attack-elmedia/
- virustotal.comhttps://www.virustotal.com/gui/file/05a2adb266ec6c0ba9ed176d87d8530e71e845348c13caf9f60049760c312cd3/behavior
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: macOS SIP Status Enumeration via csrutil status
id: 5a4c79c5-28aa-42a8-ad08-f6044b61b5b4
status: test
description: This rule flags process executions of /csrutil with the argument indicating “status”, which enumerates the current System Integrity Protection (SIP) state. Attackers often perform this post-exploitation check to understand available security restrictions before attempting further actions. It relies on macOS process creation telemetry capturing the executable path and command-line arguments.
references:
- https://ss64.com/osx/csrutil.html
- https://objective-see.org/blog/blog_0x6D.html
- https://www.welivesecurity.com/2017/10/20/osx-proton-supply-chain-attack-elmedia/
- https://www.virustotal.com/gui/file/05a2adb266ec6c0ba9ed176d87d8530e71e845348c13caf9f60049760c312cd3/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2024-01-02
tags:
- attack.discovery
- attack.t1518.001
logsource:
product: macos
category: process_creation
detection:
selection:
Image|endswith: /csrutil
CommandLine|contains: status
condition: selection
falsepositives:
- Legitimate administration activities
level: low
license: DRL-1.1
related:
- id: 53821412-17b0-4147-ade0-14faae67d54b
type: derived