macOS Emond Launch Daemon Rule Install Monitoring via plist and emondClients Paths

Alerts on macOS Emond rule plist or emond client database changes that may indicate persistence setup.

FreeReviewedSigma · Medium · v2
Product
macos
Category
file_event
Author
Alejandro Ortuno, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-23
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags file creation or modification events involving macOS Emond configuration files placed under /etc/emond.d/rules/ with .plist extensions, as well as changes to /private/var/db/emondClients/. Adversaries can use Emond launch daemon rules to establish persistence and potentially trigger actions that lead to elevated privileges. The detection relies on file event telemetry capturing TargetFilename values for these specific directories and filename patterns.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.