heroui logo

Persistence via a Hidden Plist Filename via macOS Security Events

Elastic Detection Rules

View Source
Summary
This rule detects persistence attempts on macOS by identifying the registration of a launch item (LaunchAgent or LaunchDaemon) whose plist filename starts with a dot (e.g., .com.evil.agent.plist). It leverages data from the macOS Security Events integration to report the plist path, item type (per-user Launch Agent or system-wide Launch Daemon), and the target executable. A dot-prefixed plist is commonly used to hide the persistence item from standard directory listings while remaining functional, making this pattern suspicious. The rule maps to MITRE ATT&CK techniques for Boot/Logon Autostart Execution (T1547) and its subtechniques related to plist modification (T1547.011) as well as Launch Agent/Launch Daemon creation (T1543.001/T1543.004). Investigators can use the emitted fields to determine legitimacy, scope, and the executable’s behavior, and coordinate containment or remediation as needed.
Categories
  • macOS
  • Endpoint
Data Sources
  • Process
  • File
  • Logon Session
ATT&CK Techniques
  • T1547
  • T1547.011
  • T1543
  • T1543.001
  • T1543.004
  • T1564
  • T1564.001
Created: 2026-09-22