1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1553.001 Gatekeeper Bypass — Attack Simulation

Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper…

Technique description

Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper…

At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

  • Gatekeeper Bypass

    Procedure fb3d46c6-9480-4803-8d7d-ce676e1f1a9b; elevation not declared required; cleanup not declared. Not executed or individually validated.

Connected ecosystem references

Linked tags

Detection and collection

T1553.001 detection workspace

Attack tools

No reviewed association in this snapshot.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.