macOS: JAMF CLI (jamf) execution for account and MDM management

Flags macOS executions of the JAMF CLI with command-line actions tied to account, MDM, and framework changes.

FreeReviewedSigma · Low · v2
Product
macos
Category
process_creation
Author
Jay Pandit (SigmaHQ), DRL 1.1
Published
2023-08-22
Updated
2026-07-31

What it detects

This rule identifies process executions where the macOS binary path ends with '/jamf' and the command line contains specific JAMF CLI subcommands. Attackers could abuse the JAMF tool to create or modify user accounts and manage or remove MDM-related components, potentially bypassing security controls. Detection relies on macOS process creation telemetry, including the executable path and command-line arguments.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.