{"id":"23c43900-e732-45a4-8354-63e4a6c187ce","title":"MacOS Emond Launch Daemon","description":"Detects additions to the Emond Launch Daemon that adversaries may use to gain persistence and elevate privileges.","author":"Alejandro Ortuno, oscd.community","status":"test","level":"medium","date":"2020-10-23","modified":"2021-11-27","tags":["attack.persistence","attack.privilege-escalation","attack.t1546.014"],"technique_ids":["T1546.014"],"logsource":{"category":"file_event","product":"macos"},"falsepositives":["Legitimate administration activities"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.014/T1546.014.md","https://posts.specterops.io/leveraging-emond-on-macos-for-persistence-a040a2785124"],"source_path":"rules/macos/file_event/file_event_macos_emond_launch_daemon.yml","source_sha256":"871b7f4de0eec009f3c2b86a4d0f9d189ef65a3b8493ec12737ba4538f89877a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/macos/file_event/file_event_macos_emond_launch_daemon.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: MacOS Emond Launch Daemon\nid: 23c43900-e732-45a4-8354-63e4a6c187ce\nstatus: test\ndescription: Detects additions to the Emond Launch Daemon that adversaries may use to gain persistence and elevate privileges.\nreferences:\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.014/T1546.014.md\n    - https://posts.specterops.io/leveraging-emond-on-macos-for-persistence-a040a2785124\nauthor: Alejandro Ortuno, oscd.community\ndate: 2020-10-23\nmodified: 2021-11-27\ntags:\n    - attack.persistence\n    - attack.privilege-escalation\n    - attack.t1546.014\nlogsource:\n    category: file_event\n    product: macos\ndetection:\n    selection_1:\n        TargetFilename|contains: '/etc/emond.d/rules/'\n        TargetFilename|endswith: '.plist'\n    selection_2:\n        TargetFilename|contains: '/private/var/db/emondClients/'\n    condition: 1 of selection_*\nfalsepositives:\n    - Legitimate administration activities\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1546.014","id":"T1546.014","name":"Emond","page":"techniques/enterprise/T1546.014/"}],"data_path":"data/detection-rules/23c43900-e732-45a4-8354-63e4a6c187ce.json","kind":"sigma"}
