macOS csrutil Used to Disable System Integrity Protection (SIP)
Detects macOS processes running csrutil to disable SIP by matching /csrutil with a command line containing 'disable'.
FreeUnreviewedSigmamediumv1
macos-csrutil-used-to-disable-system-integrity-protection-sip-3603f18a
title: macOS csrutil Used to Disable System Integrity Protection (SIP)
id: 384d54eb-69a4-4789-baad-21ca59af1cbe
status: test
description: This rule flags process executions on macOS where csrutil is invoked with the intent to disable System Integrity Protection. Disabling SIP can reduce operating system protections, which attackers may use to persist or conduct post-exploitation activities. Telemetry relied on includes macOS process creation events capturing the binary name ending in /csrutil and command-line text containing disable.
references:
- https://ss64.com/osx/csrutil.html
- https://objective-see.org/blog/blog_0x6D.html
- https://www.welivesecurity.com/2017/10/20/osx-proton-supply-chain-attack-elmedia/
- https://www.virustotal.com/gui/file/05a2adb266ec6c0ba9ed176d87d8530e71e845348c13caf9f60049760c312cd3/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2024-01-02
tags:
- attack.discovery
- attack.t1518.001
logsource:
product: macos
category: process_creation
detection:
selection:
Image|endswith: /csrutil
CommandLine|contains: disable
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 3603f18a-ec15-43a1-9af2-d196c8a7fec6
type: derived
What it detects
This rule flags process executions on macOS where csrutil is invoked with the intent to disable System Integrity Protection. Disabling SIP can reduce operating system protections, which attackers may use to persist or conduct post-exploitation activities. Telemetry relied on includes macOS process creation events capturing the binary name ending in /csrutil and command-line text containing disable.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.