macOS Sysctl Execution for System Hardware/Kernel Discovery

Flags macOS sysctl commands querying hw., kern., or machdep. values for system discovery.

FreeUnreviewedSigmamediumv1
title: macOS Sysctl Execution for System Hardware/Kernel Discovery
id: c315ee44-6669-4fc0-a90d-6e6336e54757
status: test
description: This rule identifies process executions of sysctl on macOS when the command line includes sysctl and targets hardware or kernel-related keys (hw., kern., machdep.). System information discovery like this can support reconnaissance and environment awareness by malware or other stealthy tooling. It relies on process creation telemetry, matching the executable path ending with /sysctl and the presence of the expected sysctl argument prefixes in the command line.
references:
  - https://www.loobins.io/binaries/sysctl/#
  - https://evasions.checkpoint.com/techniques/macos.html
  - https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/
  - https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/
  - https://objective-see.org/blog/blog_0x1E.html
  - https://www.virustotal.com/gui/file/1c547a064494a35d6b5e6b459de183ab2720a22725e082bed6f6629211f7abc1/behavior
  - https://www.virustotal.com/gui/file/b4b1fc65f87b3dcfa35e2dbe8e0a34ad9d8a400bec332025c0a2e200671038aa/behavior
  - https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysctl_discovery.yml
author: Pratinav Chandra, Huntrule Team
date: 2024-05-27
tags:
  - attack.stealth
  - attack.t1497.001
  - attack.discovery
  - attack.t1082
logsource:
  product: macos
  category: process_creation
detection:
  selection_img:
    - Image|endswith: /sysctl
    - CommandLine|contains: sysctl
  selection_cmd:
    CommandLine|contains:
      - hw.
      - kern.
      - machdep.
  condition: all of selection_*
falsepositives:
  - Legitimate administrative activities
level: medium
license: DRL-1.1
related:
  - id: 6ff08e55-ea53-4f27-94a1-eff92e6d9d5c
    type: derived

What it detects

This rule identifies process executions of sysctl on macOS when the command line includes sysctl and targets hardware or kernel-related keys (hw., kern., machdep.). System information discovery like this can support reconnaissance and environment awareness by malware or other stealthy tooling. It relies on process creation telemetry, matching the executable path ending with /sysctl and the presence of the expected sysctl argument prefixes in the command line.

Known false positives

  • Legitimate administrative activities

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.