1200KM / detection
T1543.001 Launch Agent — Detection Rules
Detection workspace for T1543.001 Launch Agent: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Launch Agent/Daemon Execution Via Launchctl · test · medium · {"category":"process_creation","product":"macos"}
- Potential Persistence Via PlistBuddy · test · high · {"category":"process_creation","product":"macos"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0434 Detection of Launch Agent Creation or Modification on macOS
AN1208 Analytic 1208
Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1543.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.