macOS SIP Status Enumeration via csrutil status

Flags execution of "csrutil status" on macOS to enumerate System Integrity Protection state.

FreeReviewedSigma · Low · v2
Product
macos
Category
process_creation
Author
Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
Published
2024-01-02
Updated
2026-07-31
title: macOS SIP Status Enumeration via csrutil status
id: 5a4c79c5-28aa-42a8-ad08-f6044b61b5b4
status: test
description: This rule flags process executions of /csrutil with the argument indicating “status”, which enumerates the current System Integrity Protection (SIP) state. Attackers often perform this post-exploitation check to understand available security restrictions before attempting further actions. It relies on macOS process creation telemetry capturing the executable path and command-line arguments.
references:
  - https://ss64.com/osx/csrutil.html
  - https://objective-see.org/blog/blog_0x6D.html
  - https://www.welivesecurity.com/2017/10/20/osx-proton-supply-chain-attack-elmedia/
  - https://www.virustotal.com/gui/file/05a2adb266ec6c0ba9ed176d87d8530e71e845348c13caf9f60049760c312cd3/behavior
  - https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2024-01-02
tags:
  - attack.discovery
  - attack.t1518.001
logsource:
  product: macos
  category: process_creation
detection:
  selection:
    Image|endswith: /csrutil
    CommandLine|contains: status
  condition: selection
falsepositives:
  - Legitimate administration activities
level: low
license: DRL-1.1
related:
  - id: 53821412-17b0-4147-ade0-14faae67d54b
    type: derived