macOS Process Execution Traces Indicating WizardUpdate Downloader/C2 Staging

Flags macOS process creations showing curl+eval execution and intermediate agent indicators associated with WizardUpdate activity.

FreeReviewedSigma · High · v2
Product
macos
Category
process_creation
Author
Tim Rauch (rule), Elastic (idea) (SigmaHQ), DRL 1.1
Published
2022-10-17
Updated
2026-07-31

What it detects

This rule identifies macOS process execution patterns consistent with WizardUpdate activity, specifically shell and curl commands involved in staged execution. Attackers commonly use these staging behaviors to fetch payload components and chain execution via shell evaluation, increasing the likelihood of additional malicious payloads. Telemetry relies on process creation events containing executable paths and command-line content matching the defined curl/sh patterns.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.