Vendor: Apple

June 14, 2023 · View on GitHub

Product: macOS

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
4019711
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accesslocal-logon
osx-local-logon
T1078 - Valid Accounts
T1078.003 - Valid Accounts: Local Accounts
  • 22 Rules
  • 10 Models
Compromised Credentialslocal-logon
osx-local-logon
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
  • 27 Rules
  • 12 Models
Lateral Movementlocal-logon
osx-local-logon
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
  • 1 Rules
Malwarelocal-logon
osx-local-logon
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
TA0002 - TA0002
  • 5 Rules
  • 2 Models
Privilege Abuselocal-logon
osx-local-logon
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 9 Rules
  • 6 Models
Privilege Escalationlocal-logon
osx-local-logon
T1078 - Valid Accounts
T1555.005 - T1555.005
  • 2 Rules
  • 1 Models
Privileged Activitylocal-logon
osx-local-logon
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 11 Rules
  • 5 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Ticket

Valid Accounts: Local Accounts

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Use Alternate Authentication Material