Files
splunk-security_content/stories/macos_post_exploitation.yml

23 lines
941 B
YAML

name: MacOS Post-Exploitation
id: bae14f9c-929d-4e2b-8fe7-e4680e0edbbb
version: 2
creation_date: '2026-04-14'
modification_date: '2026-05-13'
author: Raven Tait, Splunk
status: production
description: This analytic story identifies popular MacOS post exploitation tools such as MacPEAS, MacShellSwift, EvilOSX, chainbreaker, etc
narrative: These tools allow operators find possible exploits or paths for privilege escalation based on stored credentials, user permissions, kernel version and distro version.
references:
- https://attack.mitre.org/matrices/enterprise/macos/
- https://github.com/UnsaltedHash42/macPEAS
- https://github.com/cedowens/MacShellSwift/tree/master/MacShellSwift
- https://github.com/Marten4n6/EvilOSX
- https://github.com/n0fate/chainbreaker
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection