heroui logo

Modification of Safari Settings via Defaults Command

Elastic Detection Rules

View Source
Summary
This detection rule monitors modifications to Safari settings on macOS systems, specifically through the use of the 'defaults' command. Adversaries may exploit this command to change browser configurations (e.g., enabling JavaScript execution via Apple Events), potentially leading to browser hijacking or other malicious activities. The rule captures process events where the 'defaults' command is executed with arguments targeting Safari, while excluding certain benign changes to prevent false positives. The threat detection relies on data from the Elastic Defend integration, focusing on identifying unauthorized adjustments to user preferences that could signify adverse actions.
Categories
  • Endpoint
  • macOS
  • Cloud
Data Sources
  • Process
  • Application Log
  • Sensor Health
ATT&CK Techniques
  • T1562
  • T1562.001
Created: 2021-01-14