macOS Sysctl Execution for System Hardware/Kernel Discovery
Flags macOS sysctl commands querying hw., kern., or machdep. values for system discovery.
FreeUnreviewedSigmamediumv1
macos-sysctl-execution-for-system-hardware-kernel-discovery-6ff08e55
title: macOS Sysctl Execution for System Hardware/Kernel Discovery
id: c315ee44-6669-4fc0-a90d-6e6336e54757
status: test
description: This rule identifies process executions of sysctl on macOS when the command line includes sysctl and targets hardware or kernel-related keys (hw., kern., machdep.). System information discovery like this can support reconnaissance and environment awareness by malware or other stealthy tooling. It relies on process creation telemetry, matching the executable path ending with /sysctl and the presence of the expected sysctl argument prefixes in the command line.
references:
- https://www.loobins.io/binaries/sysctl/#
- https://evasions.checkpoint.com/techniques/macos.html
- https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/
- https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/
- https://objective-see.org/blog/blog_0x1E.html
- https://www.virustotal.com/gui/file/1c547a064494a35d6b5e6b459de183ab2720a22725e082bed6f6629211f7abc1/behavior
- https://www.virustotal.com/gui/file/b4b1fc65f87b3dcfa35e2dbe8e0a34ad9d8a400bec332025c0a2e200671038aa/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysctl_discovery.yml
author: Pratinav Chandra, Huntrule Team
date: 2024-05-27
tags:
- attack.stealth
- attack.t1497.001
- attack.discovery
- attack.t1082
logsource:
product: macos
category: process_creation
detection:
selection_img:
- Image|endswith: /sysctl
- CommandLine|contains: sysctl
selection_cmd:
CommandLine|contains:
- hw.
- kern.
- machdep.
condition: all of selection_*
falsepositives:
- Legitimate administrative activities
level: medium
license: DRL-1.1
related:
- id: 6ff08e55-ea53-4f27-94a1-eff92e6d9d5c
type: derived
What it detects
This rule identifies process executions of sysctl on macOS when the command line includes sysctl and targets hardware or kernel-related keys (hw., kern., machdep.). System information discovery like this can support reconnaissance and environment awareness by malware or other stealthy tooling. It relies on process creation telemetry, matching the executable path ending with /sysctl and the presence of the expected sysctl argument prefixes in the command line.
Known false positives
- Legitimate administrative activities
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.