macOS Startup Item Plist Created in StartupItems Folders

Alerts on creation of startup item .plist files in macOS StartupItems directories, potential boot persistence setup.

FreeReviewedSigma · Low · v2
Product
macos
Category
file_event
Author
Alejandro Ortuno, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-14
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies the creation of a macOS startup item plist file within the StartupItems directories under /Library or /System. Startup items are executed during boot to establish persistence, so unauthorized creation of these plist files can indicate attempted persistence via system startup configuration. It relies on file creation telemetry capturing the TargetFilename path and extension, matching *.plist under the specified directories.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.