macOS dscl Adds User to Admin Group via -append /Groups/admin GroupMembership

Flags dscl commands on macOS that append a user into the local admin group membership.

FreeReviewedSigma · Medium · v2
Product
macos
Category
process_creation
Author
Sohan G (D4rkCiph3r) (SigmaHQ), DRL 1.1
Published
2023-03-19
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects macOS process executions where dscl is used with parameters that append a specified value to the /Groups/admin GroupMembership attribute. Such activity can grant administrative privileges to a newly created or existing account, supporting persistence and privilege escalation. Telemetry relies on process creation events capturing the process image name/path and command-line arguments including the -append, /Groups/admin, and GroupMembership components.

Related detections5 linkedT1078.003 — drag to rearrange
Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry
macOS dseditgroup Used to Add User to admin Group
macOS Root Account Enable Attempt via dsenableroot
macOS sysadminctl Used to Add User to Admin Group
Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
macOS dscl Adds User to Admin Group via -append /Groups/admin GroupMembership
Pivot detection · T1078.003 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.