macOS detections
Clankerusecase tracks 66 detection use cases covering the macOS attack surface across 53 MITRE ATT&CK techniques.
Detections targeting macOS endpoints — osascript / launchd / .plist persistence / Mach-O execution.
66Use cases
53Techniques
32Articles
5Kill-chain phases
Top techniques on macOS (25)
T1543.001Launch Agent17T1105Ingress Tool Transfer15T1204.002Malicious File12T1195.002Compromise Software Supply Chain12T1059.004Unix Shell9T1036.005Match Legitimate Resource Name or Location8T1071.001Web Protocols5T1543.002Systemd Service5T1059.001PowerShell4T1204.004Malicious Copy and Paste3T1059Command and Scripting Interpreter3T1543.004Launch Daemon3T1027Obfuscated Files or Information3T1059.006Python3T1555Credentials from Password Stores3T1546.016Installer Packages3T1140Deobfuscate/Decode Files or Information2T1539Steal Web Session Cookie2T1005Data from Local System2T1041Exfiltration Over C2 Channel2T1567Exfiltration Over Web Service2T1059.002AppleScript2T1564.001Hidden Files and Directories2T1555.001Keychain2T1204.003Malicious Image2