macOS System Network Connection Discovery via who, w, last, lsof, or netstat

Flags macOS process executions of who/w/last/lsof/netstat used to discover network or session information.

FreeReviewedSigma · Informational · v2
Product
macos
Category
process_creation
Author
Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-19
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions on macOS where the command image name ends with one of: /who, /w, /last, /lsof, or /netstat. These utilities are commonly used to enumerate system users and active network connections, which can support discovery and reconnaissance prior to further activity. It relies on process creation telemetry capturing the process image path for the executed command.

Related detections9 linkedT1049 — drag to rearrange
Suspicious Java Process Spawning Reconnaissance Commands via Cleo MFT (via process_creation)
Suspicious Reconnaissance Spawned by Injected SearchProtocolHost via process_creation
Windows Process Creation Signals for Pikabot System Discovery
Windows Net.exe Network Connections Discovery via Use Sessions Query
PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Linux System Network Connections Discovery via who, w, last, lsof, or netstat
Cisco AAA discovery via show/dir commands
macOS System Network Connection Discovery via who, w, last, lsof, or netstat
Pivot detection · T1049 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.