macOS Process Activity: grep for 'password' and laZagne Credential Extraction
Detects macOS executions of grep targeting 'password' strings and laZagne, suggesting local credential extraction attempts.
FreeUnreviewedSigmahighv1
macos-process-activity-grep-for-password-and-lazagne-credential-extraction-53b1b378
title: "macOS Process Activity: grep for 'password' and laZagne Credential Extraction"
id: 143b6162-e2ac-472d-b189-1057accaf735
status: test
description: This rule flags macOS process creation events where the command line indicates password searching via grep and/or the use of laZagne. Attackers may run these tools to locate and extract credentials from files or system data during credential access. It relies on process creation telemetry capturing the executed image path and command-line arguments, specifically matching for grep usage containing 'password' and command lines containing 'laZagne'.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.001/T1552.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_find_cred_in_files.yml
author: Igor Fits, Mikhail Larin, oscd.community, Huntrule Team
date: 2020-10-19
modified: 2021-11-27
tags:
- attack.credential-access
- attack.t1552.001
logsource:
product: macos
category: process_creation
detection:
selection1:
Image|endswith: /grep
CommandLine|contains: password
selection2:
CommandLine|contains: laZagne
condition: 1 of selection*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 53b1b378-9b06-4992-b972-dde6e423d2b4
type: derived
What it detects
This rule flags macOS process creation events where the command line indicates password searching via grep and/or the use of laZagne. Attackers may run these tools to locate and extract credentials from files or system data during credential access. It relies on process creation telemetry capturing the executed image path and command-line arguments, specifically matching for grep usage containing 'password' and command lines containing 'laZagne'.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.