macOS launchctl submits/loads/starts Launch Agents and Daemons via process execution
Flags launchctl usage on macOS to submit, load, or start Launch Agents/Daemons, a common persistence mechanism.
FreeUnreviewedSigmamediumv1
macos-launchctl-submits-loads-starts-launch-agents-and-daemons-via-process-execu-ae9d710f
title: macOS launchctl submits/loads/starts Launch Agents and Daemons via process execution
id: e9e6e383-ffed-48a5-a2e9-e310ee42dfd6
status: test
description: This rule identifies macOS process executions where launchctl is invoked with command-line arguments consistent with submitting, loading, or starting Launch Agents/Launch Daemons. Attackers use launchctl to establish persistence by registering or activating background services without relying on interactive execution. Telemetry relies on macOS process creation data, specifically the launching binary path ending with /launchctl and the presence of submit, load, and start in the command line.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.001/T1569.001.md
- https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/
- https://www.welivesecurity.com/2020/07/16/mac-cryptocurrency-trading-application-rebranded-bundled-malware/
- https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html
- https://www.loobins.io/binaries/launchctl/
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_launchctl_execution.yml
author: Pratinav Chandra, Huntrule Team
date: 2024-05-13
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.t1569.001
- attack.t1543.001
- attack.t1543.004
logsource:
category: process_creation
product: macos
detection:
selection:
Image|endswith: /launchctl
CommandLine|contains:
- submit
- load
- start
condition: selection
falsepositives:
- Legitimate administration activities is expected to trigger false positives. Investigate the command line being passed to determine if the service or launch agent are suspicious.
level: medium
license: DRL-1.1
related:
- id: ae9d710f-dcd1-4f75-a0a5-93a73b5dda0e
type: derived
What it detects
This rule identifies macOS process executions where launchctl is invoked with command-line arguments consistent with submitting, loading, or starting Launch Agents/Launch Daemons. Attackers use launchctl to establish persistence by registering or activating background services without relying on interactive execution. Telemetry relies on macOS process creation data, specifically the launching binary path ending with /launchctl and the presence of submit, load, and start in the command line.
Known false positives
- Legitimate administration activities is expected to trigger false positives. Investigate the command line being passed to determine if the service or launch agent are suspicious.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.