Skip to content

Snap Mac Detections#3935

Open
RavenTait wants to merge 1 commit intodevelopfrom
mac_from_snap
Open

Snap Mac Detections#3935
RavenTait wants to merge 1 commit intodevelopfrom
mac_from_snap

Conversation

@RavenTait
Copy link
Contributor

Added new Mac OS detections and analytic stories

Detections:

  • MacOS Account Created
  • MacOS Data Chunking
  • MacOS Gatekeeper Bypass
  • MacOS Hidden Files and Directories
  • MacOS Kextload Usage
  • MacOS Keychains Dumped
  • MacOS Log Removal
  • MacOS Loginhook Persistence
  • MacOS Network Share Discovery

Stories

  • MacOS Post-Exploitation
  • MacOS Persistence Techniques
  • MacOS Privilege Escalation

@RavenTait RavenTait added the WIP DO NOT MERGE Work in Progress label Mar 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Detections Stories WIP DO NOT MERGE Work in Progress

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant