Suspicious macOS SSH Loopback Connection for TCC Bypass

PremiumReviewedSigma · Low · v1
Product
macos
Category
process_creation
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects an SSH client connecting to the local loopback address on macOS. It maps to a technique where an attacker uses ssh to localhost so the spawned session inherits full disk access granted to the SSH daemon, bypassing the TCC privacy prompt. Detecting loopback SSH can surface abuse of remote services for privacy control evasion.

Related detections9 linkedT1021.004 — drag to rearrange
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Bitbucket Audit: Global SSH Settings Changed
Bitbucket Audit: SSH User Login Failures
OpenSSH Server (sshd) Listening on SSH Socket on Windows
Suspicious macOS SSH Loopback Connection for TCC Bypass
Pivot detection · T1021.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.