macOS firmwarepasswd Command-Line Manipulation

Alerts on firmwarepasswd usage on macOS indicating firmware password set, full, delete, or check actions.

FreeReviewedSigma · Medium · v2
Product
macos
Category
process_creation
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-30
Updated
2026-07-31

What it detects

This rule flags process executions of /usr/sbin/firmwarepasswd with command-line arguments associated with password management actions such as setting, full updates, deletion, or checks. Attackers may use firmware password manipulation to alter device security controls to persist access before the operating system loads. It relies on macOS process creation telemetry, specifically the executed image path and command-line contents of firmwarepasswd.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.