Suspicious Gatekeeper Quarantine Database Query via sqlite3

PremiumReviewedSigma · High · v1
Product
macos
Category
process_creation
Author
HuntRule
Published
2026-08-04
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects sqlite3 querying the LSQuarantineEvents database, an anti-analysis check used by macOS Shlayer and Bundlore to inspect how a sample was downloaded and whether Gatekeeper flagged it. Reading this quarantine store helps the adware tailor its behavior and evade detonation environments.

Related detections6 linkedT1553.001 — drag to rearrange
Suspicious Removal of the macOS Quarantine Attribute via Xattr (via process_creation)
Untrusted Disabling of macOS Gatekeeper via Spctl (via process_creation)
Suspicious Interpreter Spawned by launchd from Application Bundle
Suspicious File Download to tmp and Quarantine Removal via curl and xattr
Suspicious macOS Quarantine Attribute Removal via xattr (via process_creation)
macOS Gatekeeper bypass attempt using xattr to remove com.apple.quarantine
Suspicious Gatekeeper Quarantine Database Query via sqlite3
Pivot detection · T1553.001 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.