macOS Process Creation: Command Line Access to Shell History Files

Flags macOS command lines referencing common shell history files, which may indicate credential access or cover-tracks behavior.

FreeReviewedSigma · Medium · v2
Product
macos
Category
process_creation
Author
Mikhail Larin, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-17
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags macOS process executions where the command line contains references to common shell history files (e.g., .bash_history, .zsh_history, .history). Attackers may read, modify, or clear these files to discover prior commands or to cover their tracks. The detection relies on process creation telemetry and specifically inspects the command line text for these history file names.

Related detections2 linkedT1552.003 — drag to rearrange
Linux: Command-Line Access to Shell History Files via execve
Cisco AAA: Detection of 'show history' and 'show logging' command input
macOS Process Creation: Command Line Access to Shell History Files
Pivot detection · T1552.003 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.