heroui logo

SSFileCopySender Executed as Root

Elastic Detection Rules

View Source
Summary
Detects the macOS Screen Sharing file-copy helper SSFileCopySender executing with root privileges (UID/GID 0/80). This is abnormal because legitimate file transfers run in the remote user’s context, and root execution can indicate a pre-authentication exploitation path for Screen Sharing (CVE-2026-65400), where flawed SRP validation may allow privileged operations before login. The 0/80 UID/GID pair may reflect an initial exploitation attempt and can be evaded if the attacker enumerates another local account. Treat this as a tripwire and correlate with the related SSFileCopyReceiver rule (Writing to Common Persistence Locations) to confirm persistence or broader compromise. Investigation should focus on how Screen Sharing was reached, whether remote access was expected, and whether privilege-escalation or post-exploitation activity followed (e.g., shell, scripting, payload deployment, or persistence). This rule maps to potential initial access and privilege escalation techniques in MITRE ATT&CK (T1190, Exploit Public-Facing Application; T1068, Exploitation for Privilege Escalation).
Categories
  • Endpoint
  • macOS
Data Sources
  • Process
ATT&CK Techniques
  • T2012
  • T1190
  • T1068
Created: 2026-08-19