mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
23 lines
941 B
YAML
23 lines
941 B
YAML
name: MacOS Post-Exploitation
|
|
id: bae14f9c-929d-4e2b-8fe7-e4680e0edbbb
|
|
version: 2
|
|
creation_date: '2026-04-14'
|
|
modification_date: '2026-05-13'
|
|
author: Raven Tait, Splunk
|
|
status: production
|
|
description: This analytic story identifies popular MacOS post exploitation tools such as MacPEAS, MacShellSwift, EvilOSX, chainbreaker, etc
|
|
narrative: These tools allow operators find possible exploits or paths for privilege escalation based on stored credentials, user permissions, kernel version and distro version.
|
|
references:
|
|
- https://attack.mitre.org/matrices/enterprise/macos/
|
|
- https://github.com/UnsaltedHash42/macPEAS
|
|
- https://github.com/cedowens/MacShellSwift/tree/master/MacShellSwift
|
|
- https://github.com/Marten4n6/EvilOSX
|
|
- https://github.com/n0fate/chainbreaker
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|