1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1569.001 Launchctl — Attack Simulation

Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input. Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries…

Technique description

Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input. Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries…

At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

  • Launchctl

    Procedure 6fb61988-724e-4755-a595-07743749d4e2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.

Connected ecosystem references

Linked tags

Detection and collection

T1569.001 detection workspace

Attack tools

No reviewed association in this snapshot.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.