macOS Root Account Enable Attempt via dsenableroot

Detects macOS attempts to enable the root account by running /dsenableroot.

FreeReviewedSigma · Medium · v2
Product
macos
Category
process_creation
Author
Sohan G (D4rkCiph3r) (SigmaHQ), DRL 1.1
Published
2023-08-22
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion

What it detects

This rule flags process executions of the macOS utility dsenableroot when invoked to enable the root account. Enabling a root account can provide attackers with persistent, high-privilege access and simplifies subsequent privilege escalation and stealth. The detection relies on process creation telemetry, matching the executable path ending in /dsenableroot.

Related detections9 linkedT1078 — drag to rearrange
macOS: Guest account enabled via sysadminctl
Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
Suspicious SQL Server - Connection Attempt Using a Disabled Account (via application)
Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
Suspicious Snowflake Anomalous Client Application Associated With UNC5537 (via cloud)
macOS Root Account Enable Attempt via dsenableroot
Pivot detection · T1078 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.