macOS detections
Clankerusecase tracks 78 detection use cases covering the macOS attack surface across 62 MITRE ATT&CK techniques.
Detections targeting macOS endpoints — osascript / launchd / .plist persistence / Mach-O execution.
78Use cases
62Techniques
35Articles
6Kill-chain phases
Top techniques on macOS (25)
T1543.001Launch Agent19T1105Ingress Tool Transfer16T1059.004Unix Shell12T1195.002Compromise Software Supply Chain11T1204.002Malicious File10T1036.005Match Legitimate Resource Name or Location8T1071.001Web Protocols7T1543.002Systemd Service5T1204.004Malicious Copy and Paste4T1059.001PowerShell4T1555.001Keychain4T1543.004Launch Daemon4T1190Exploit Public-Facing Application3T1539Steal Web Session Cookie3T1041Exfiltration Over C2 Channel3T1059Command and Scripting Interpreter3T1195.001Compromise Software Dependencies and Development Tools3T1059.006Python3T1555Credentials from Password Stores3T1546.016Installer Packages3T1140Deobfuscate/Decode Files or Information2T1555.003Credentials from Web Browsers2T1005Data from Local System2T1059.002AppleScript2T1564.001Hidden Files and Directories2