heroui logo

Launch Item Registration with Suspicious Executable Path via macOS Security Events

Elastic Detection Rules

View Source
Summary
This detection rule identifies macOS launch items (launch agents and launch daemons) whose target executable is registered from a temporary or world-writable location, using macOS Security Events telemetry. It watches for launch item registrations and reports the plist path, item type, and executable when the path matches common insecure locations. Legitimate software typically executes from system or application directories; executables staged in /tmp, /private/tmp, /var/tmp, /var/folders, /Users/Shared, or user-writable paths (e.g., Downloads, Public, Library/Caches) are treated as suspicious and warrant investigation. The rule maps to MITRE ATT&CK technique T1543 (Create or Modify System Process) with subtechniques T1543.001 (Launch Agent) and T1543.004 (Launch Daemon) under the Persistence tactic (TA0003). The ESQL query extracts Esql.plist_path, Esql.item_type, and Esql.executable from macos.process_execution_monitoring data and flags executables residing in temp-like or user-writable directories. The alert payload is designed for rapid triage and follow-up investigations of potential malicious persistence activity.
Categories
  • macOS
  • Endpoint
Data Sources
  • Process
  • File
ATT&CK Techniques
  • T1543
  • T1543.001
  • T1543.004
Created: 2026-09-22