1200KM / detection
T1546.014 Emond — Detection Rules
Detection workspace for T1546.014 Emond: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- MacOS Emond Launch Daemon · test · medium · {"category":"file_event","product":"macos"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0555 Detection Strategy for Event Triggered Execution via emond on macOS
AN1534 Analytic 1534
Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1546.014 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.