Files
atomic-red-team/atomics/Indexes/Indexes-CSV/macos-index.csv
T
2020-11-23 13:41:01 +00:00

19 KiB

1TacticTechnique #Technique NameTest #Test NameTest GUIDExecutor Name
2privilege-escalationT1546.004.bash_profile and .bashrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
3privilege-escalationT1546.004.bash_profile and .bashrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
4privilege-escalationT1053.003Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75bash
5privilege-escalationT1053.003Cron2Cron - Add script to cron folderb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
6privilege-escalationT1546.014Emond1Persistance with Event Monitor - emond23c9c127-322b-4c75-95ca-eff464906114sh
7privilege-escalationT1543.001Launch Agent1Launch Agenta5983dee-bf6c-4eaf-951c-dbc1a7b90900bash
8privilege-escalationT1543.004Launch Daemon1Launch Daemon03ab8df5-3a6b-4417-b6bd-bb7a5cfd74cfbash
9privilege-escalationT1053.004Launchd1Event Monitor Daemon Persistence11979f23-9b9d-482a-9935-6fc9cd022c3ebash
10privilege-escalationT1037.002Logon Script (Mac)1Logon Scripts - Macf047c7de-a2d9-406e-a62b-12a09d9516f4manual
11privilege-escalationT1547.011Plist Modification1Plist Modification394a538e-09bb-4a4a-95d1-b93cf12682a8manual
12privilege-escalationT1037.004Rc.common1rc.common97a48daa-8bca-4bc0-b1a9-c1d163e762debash
13privilege-escalationT1547.007Re-opened Applications1Re-Opened Applications5fefd767-ef54-4ac6-84d3-751ab85e8abamanual
14privilege-escalationT1547.007Re-opened Applications2Re-Opened Applications5f5b71da-e03f-42e7-ac98-d63f9e0465cbsh
15privilege-escalationT1548.001Setuid and Setgid1Make and modify binary from C source896dfe97-ae43-4101-8e96-9a7996555d80sh
16privilege-escalationT1548.001Setuid and Setgid2Set a SetUID flag on file759055b3-3885-4582-a8ec-c00c9d64dd79sh
17privilege-escalationT1548.001Setuid and Setgid3Set a SetGID flag on filedb55f666-7cba-46c6-9fe6-205a05c3242csh
18privilege-escalationT1037.005Startup Items1Add file to Local Library StartupItems134627c3-75db-410e-bff8-7a920075f198sh
19privilege-escalationT1548.003Sudo and Sudo Caching1Sudo usage150c3a08-ee6e-48a6-aeaf-3659d24ceb4esh
20privilege-escalationT1548.003Sudo and Sudo Caching2Unlimited sudo cache timeouta7b17659-dd5e-46f7-b7d1-e6792c91d0bcsh
21privilege-escalationT1548.003Sudo and Sudo Caching3Disable tty_tickets for sudo caching91a60b03-fb75-4d24-a42e-2eb8956e8de1sh
22privilege-escalationT1546.005Trap1Trapa74b2e07-5952-4c03-8b56-56274b076b61sh
23persistenceT1546.004.bash_profile and .bashrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
24persistenceT1546.004.bash_profile and .bashrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
25persistenceT1176Browser Extensions1Chrome (Developer Mode)3ecd790d-2617-4abf-9a8c-4e8d47da9ee1manual
26persistenceT1176Browser Extensions2Chrome (Chrome Web Store)4c83940d-8ca5-4bb2-8100-f46dc914bc3fmanual
27persistenceT1176Browser Extensions3Firefoxcb790029-17e6-4c43-b96f-002ce5f10938manual
28persistenceT1176Browser Extensions4Edge Chromium Addon - VPN3d456e2b-a7db-4af8-b5b3-720e7c4d9da5manual
29persistenceT1053.003Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75bash
30persistenceT1053.003Cron2Cron - Add script to cron folderb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
31persistenceT1546.014Emond1Persistance with Event Monitor - emond23c9c127-322b-4c75-95ca-eff464906114sh
32persistenceT1543.001Launch Agent1Launch Agenta5983dee-bf6c-4eaf-951c-dbc1a7b90900bash
33persistenceT1543.004Launch Daemon1Launch Daemon03ab8df5-3a6b-4417-b6bd-bb7a5cfd74cfbash
34persistenceT1053.004Launchd1Event Monitor Daemon Persistence11979f23-9b9d-482a-9935-6fc9cd022c3ebash
35persistenceT1136.001Local Account2Create a user account on a MacOS system01993ba5-1da3-4e15-a719-b690d4f0f0b2bash
36persistenceT1037.002Logon Script (Mac)1Logon Scripts - Macf047c7de-a2d9-406e-a62b-12a09d9516f4manual
37persistenceT1547.011Plist Modification1Plist Modification394a538e-09bb-4a4a-95d1-b93cf12682a8manual
38persistenceT1037.004Rc.common1rc.common97a48daa-8bca-4bc0-b1a9-c1d163e762debash
39persistenceT1547.007Re-opened Applications1Re-Opened Applications5fefd767-ef54-4ac6-84d3-751ab85e8abamanual
40persistenceT1547.007Re-opened Applications2Re-Opened Applications5f5b71da-e03f-42e7-ac98-d63f9e0465cbsh
41persistenceT1098.004SSH Authorized Keys1Modify SSH Authorized Keys342cc723-127c-4d3a-8292-9c0c6b4ecadcbash
42persistenceT1037.005Startup Items1Add file to Local Library StartupItems134627c3-75db-410e-bff8-7a920075f198sh
43persistenceT1546.005Trap1Trapa74b2e07-5952-4c03-8b56-56274b076b61sh
44defense-evasionT1027.001Binary Padding1Pad Binary to Change Hash - Linux/macOS ddffe2346c-abd5-4b45-a713-bf5f1ebd573ash
45defense-evasionT1070.003Clear Command History1Clear Bash history (rm)a934276e-2be5-4a36-93fd-98adbb5bd4fcsh
46defense-evasionT1070.003Clear Command History2Clear Bash history (echo)cbf506a5-dd78-43e5-be7e-a46b7c7a0a11sh
47defense-evasionT1070.003Clear Command History3Clear Bash history (cat dev/null)b1251c35-dcd3-4ea1-86da-36d27b54f31fsh
48defense-evasionT1070.003Clear Command History4Clear Bash history (ln dev/null)23d348f3-cc5c-4ba9-bd0a-ae09069f0914sh
49defense-evasionT1070.003Clear Command History6Clear history of a bunch of shells7e6721df-5f08-4370-9255-f06d8a77af4csh
50defense-evasionT1070.003Clear Command History7Clear and Disable Bash History Logging784e4011-bd1a-4ecd-a63a-8feb278512e6sh
51defense-evasionT1070.003Clear Command History8Use Space Before Command to Avoid Logging to History53b03a54-4529-4992-852d-a00b4b7215a6sh
52defense-evasionT1070.002Clear Linux or Mac System Logs1rm -rf989cc1b1-3642-4260-a809-54f9dd559683sh
53defense-evasionT1562.001Disable or Modify Tools5Disable Carbon Black Response8fba7766-2d11-4b4a-979a-1e3d9cc9a88csh
54defense-evasionT1562.001Disable or Modify Tools6Disable LittleSnitch62155dd8-bb3d-4f32-b31c-6532ff3ac6a3sh
55defense-evasionT1562.001Disable or Modify Tools7Disable OpenDNS Umbrella07f43b33-1e15-4e99-be70-bc094157c849sh
56defense-evasionT1562.001Disable or Modify Tools8Disable macOS Gatekeeper2a821573-fb3f-4e71-92c3-daac7432f053sh
57defense-evasionT1562.001Disable or Modify Tools9Stop and unload Crowdstrike Falcon on macOSb3e7510c-2d4c-4249-a33f-591a2bc83eefsh
58defense-evasionT1070.004File Deletion1Delete a single file - Linux/macOS562d737f-2fc6-4b09-8c2a-7f8ff0828480sh
59defense-evasionT1070.004File Deletion2Delete an entire folder - Linux/macOSa415f17e-ce8d-4ce2-a8b4-83b674e7017esh
60defense-evasionT1553.001Gatekeeper Bypass1Gatekeeper Bypassfb3d46c6-9480-4803-8d7d-ce676e1f1a9bsh
61defense-evasionT1562.003HISTCONTROL1Disable history collection4eafdb45-0f79-4d66-aa86-a3e2c08791f5sh
62defense-evasionT1562.003HISTCONTROL2Mac HISTCONTROL468566d5-83e5-40c1-b338-511e1659628dmanual
63defense-evasionT1564.001Hidden Files and Directories1Create a hidden file in a hidden directory61a782e5-9a19-40b5-8ba4-69a4b9f3d7besh
64defense-evasionT1564.001Hidden Files and Directories2Mac Hidden filecddb9098-3b47-4e01-9d3b-6f5f323288a9sh
65defense-evasionT1564.001Hidden Files and Directories5Hidden files3b7015f2-3144-4205-b799-b05580621379sh
66defense-evasionT1564.001Hidden Files and Directories6Hide a Directoryb115ecaf-3b24-4ed2-aefe-2fcb9db913d3sh
67defense-evasionT1564.001Hidden Files and Directories7Show all hidden files9a1ec7da-b892-449f-ad68-67066d04380csh
68defense-evasionT1564.002Hidden Users1Create Hidden User using UniqueID < 5004238a7f0-a980-4fff-98a2-dfc0a363d507sh
69defense-evasionT1564.002Hidden Users2Create Hidden User using IsHidden optionde87ed7b-52c3-43fd-9554-730f695e7f31sh
70defense-evasionT1553.004Install Root Certificate3Install root CA on macOScc4a0b8c-426f-40ff-9426-4e10e5bf4c49command_prompt
71defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification1chmod - Change file or folder mode (numeric mode)34ca1464-de9d-40c6-8c77-690adf36a135bash
72defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification2chmod - Change file or folder mode (symbolic mode)fc9d6695-d022-4a80-91b1-381f5c35aff3bash
73defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification3chmod - Change file or folder mode (numeric mode) recursivelyea79f937-4a4d-4348-ace6-9916aec453a4bash
74defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification4chmod - Change file or folder mode (symbolic mode) recursively0451125c-b5f6-488f-993b-5a32b09f7d8fbash
75defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification5chown - Change file or folder ownership and groupd169e71b-85f9-44ec-8343-27093ff3dfc0bash
76defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification6chown - Change file or folder ownership and group recursivelyb78598be-ff39-448f-a463-adbf2a5b7848bash
77defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification7chown - Change file or folder mode ownership only967ba79d-f184-4e0e-8d09-6362b3162e99bash
78defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification8chown - Change file or folder ownership recursively3b015515-b3d8-44e9-b8cd-6fa84faf30b2bash
79defense-evasionT1222.002Linux and Mac File and Directory Permissions Modification9chattr - Remove immutable file attributee7469fe2-ad41-4382-8965-99b94dd3c13fsh
80defense-evasionT1027Obfuscated Files or Information1Decode base64 Data into Scriptf45df6be-2e1e-4136-a384-8f18ab3826fbsh
81defense-evasionT1548.001Setuid and Setgid1Make and modify binary from C source896dfe97-ae43-4101-8e96-9a7996555d80sh
82defense-evasionT1548.001Setuid and Setgid2Set a SetUID flag on file759055b3-3885-4582-a8ec-c00c9d64dd79sh
83defense-evasionT1548.001Setuid and Setgid3Set a SetGID flag on filedb55f666-7cba-46c6-9fe6-205a05c3242csh
84defense-evasionT1027.002Software Packing3Binary simply packed by UPXb16ef901-00bb-4dda-b4fc-a04db5067e20sh
85defense-evasionT1027.002Software Packing4Binary packed by UPX, with modified headers4d46e16b-5765-4046-9f25-a600d3e65e4dsh
86defense-evasionT1036.006Space after Filename1Space After Filename89a7dd26-e510-4c9f-9b15-f3bae333360fmanual
87defense-evasionT1548.003Sudo and Sudo Caching1Sudo usage150c3a08-ee6e-48a6-aeaf-3659d24ceb4esh
88defense-evasionT1548.003Sudo and Sudo Caching2Unlimited sudo cache timeouta7b17659-dd5e-46f7-b7d1-e6792c91d0bcsh
89defense-evasionT1548.003Sudo and Sudo Caching3Disable tty_tickets for sudo caching91a60b03-fb75-4d24-a42e-2eb8956e8de1sh
90defense-evasionT1497.001System Checks3Detect Virtualization Environment (MacOS)a960185f-aef6-4547-8350-d1ce16680d09sh
91defense-evasionT1070.006Timestomp1Set a file's access timestamp5f9113d5-ed75-47ed-ba23-ea3573d05810sh
92defense-evasionT1070.006Timestomp2Set a file's modification timestamp20ef1523-8758-4898-b5a2-d026cc3d2c52sh
93defense-evasionT1070.006Timestomp3Set a file's creation timestamp8164a4a6-f99c-4661-ac4f-80f5e4e78d2bsh
94defense-evasionT1070.006Timestomp4Modify file timestamps using reference file631ea661-d661-44b0-abdb-7a7f3fc08e50sh
95impactT1485Data Destruction2macOS/Linux - Overwrite file with DD38deee99-fd65-4031-bec8-bfa4f9f26146bash
96impactT1496Resource Hijacking1macOS/Linux - Simulate CPU Load with Yes904a5a0e-fb02-490d-9f8d-0e256eb37549bash
97impactT1529System Shutdown/Reboot3Restart System via `shutdown` - macOS/Linux6326dbc4-444b-4c04-88f4-27e94d0327cbbash
98impactT1529System Shutdown/Reboot4Shutdown System via `shutdown` - macOS/Linux4963a81e-a3ad-4f02-adda-812343b351debash
99impactT1529System Shutdown/Reboot5Restart System via `reboot` - macOS/Linux47d0b042-a918-40ab-8cf9-150ffe919027bash
100discoveryT1217Browser Bookmark Discovery2List Mozilla Firefox Bookmark Database Files on macOS1ca1f9c7-44bc-46bb-8c85-c50e2e94267bsh
101discoveryT1217Browser Bookmark Discovery3List Google Chrome Bookmark JSON Files on macOSb789d341-154b-4a42-a071-9111588be9bcsh
102discoveryT1083File and Directory Discovery3Nix File and Diectory Discoveryffc8b249-372a-4b74-adcd-e4c0430842desh
103discoveryT1083File and Directory Discovery4Nix File and Directory Discovery 213c5e1ae-605b-46c4-a79f-db28c77ff24esh
104discoveryT1087.001Local Account1Enumerate all accounts (Local)f8aab3dd-5990-4bf8-b8ab-2226c951696fsh
105discoveryT1087.001Local Account2View sudoers accessfed9be70-0186-4bde-9f8a-20945f9370c2sh
106discoveryT1087.001Local Account3View accounts with UID 0c955a599-3653-4fe5-b631-f11c00eb0397sh
107discoveryT1087.001Local Account4List opened files by user7e46c7a5-0142-45be-a858-1a3ecb4fd3cbsh
108discoveryT1087.001Local Account6Enumerate users and groupse6f36545-dc1e-47f0-9f48-7f730f54a02esh
109discoveryT1087.001Local Account7Enumerate users and groups319e9f6c-7a9e-432e-8c62-9385c803b6f2sh
110discoveryT1069.001Local Groups1Permission Groups Discovery (Local)952931a4-af0b-4335-bbbe-73c8c5b327aesh
111discoveryT1046Network Service Scanning1Port Scan68e907da-2539-48f6-9fc9-257a78c05540sh
112discoveryT1046Network Service Scanning2Port Scan Nmap515942b0-a09f-4163-a7bb-22fefb6f185fsh
113discoveryT1135Network Share Discovery1Network Share Discoveryf94b5ad9-911c-4eff-9718-fd21899db4f7sh
114discoveryT1040Network Sniffing2Packet Capture macOS9d04efee-eff5-4240-b8d2-07792b873608bash
115discoveryT1201Password Policy Discovery7Examine password policy - macOS4b7fa042-9482-45e1-b348-4b756b2a0742bash
116discoveryT1057Process Discovery1Process Discovery - ps4ff64f0b-aaf2-4866-b39d-38d9791407ccsh
117discoveryT1018Remote System Discovery6Remote System Discovery - arp nixacb6b1ff-e2ad-4d64-806c-6c35fe73b951sh
118discoveryT1018Remote System Discovery7Remote System Discovery - sweep96db2632-8417-4dbb-b8bb-a8b92ba391desh
119discoveryT1518.001Security Software Discovery3Security Software Discovery - ps (macOS)ba62ce11-e820-485f-9c17-6f3c857cd840sh
120discoveryT1518Software Discovery3Find and Display Safari Browser Version103d6533-fd2a-4d08-976a-4a598565280fcommand_prompt
121discoveryT1497.001System Checks3Detect Virtualization Environment (MacOS)a960185f-aef6-4547-8350-d1ce16680d09sh
122discoveryT1082System Information Discovery2System Information Discoveryedff98ec-0f73-4f63-9890-6b117092aff6sh
123discoveryT1082System Information Discovery3List OS Informationcccb070c-df86-4216-a5bc-9fb60c74e27csh
124discoveryT1082System Information Discovery7Hostname Discovery486e88ea-4f56-470f-9b57-3f4d73f39133bash
125discoveryT1016System Network Configuration Discovery3System Network Configuration Discoveryc141bbdb-7fca-4254-9fd6-f47e79447e17sh
126discoveryT1016System Network Configuration Discovery6List macOS Firewall Rulesff1d8c25-2aa4-4f18-a425-fede4a41ee88bash
127discoveryT1049System Network Connections Discovery3System Network Connections Discovery Linux & MacOS9ae28d3f-190f-4fa0-b023-c7bd3e0eabf2sh
128discoveryT1033System Owner/User Discovery2System Owner/User Discovery2a9b677d-a230-44f4-ad86-782df1ef108csh
129executionT1059.002AppleScript1AppleScript3600d97d-81b9-4171-ab96-e4386506e2c2sh
130executionT1053.003Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75bash
131executionT1053.003Cron2Cron - Add script to cron folderb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
132executionT1569.001Launchctl1Launchctl6fb61988-724e-4755-a595-07743749d4e2bash
133executionT1053.004Launchd1Event Monitor Daemon Persistence11979f23-9b9d-482a-9935-6fc9cd022c3ebash
134executionT1059.004Unix Shell1Create and Execute Bash Shell Script7e7ac3ed-f795-4fa5-b711-09d6fbe9b873sh
135executionT1059.004Unix Shell2Command-Line Interfaced0c88567-803d-4dca-99b4-7ce65e7b257csh
136command-and-controlT1105Ingress Tool Transfer1rsync remote file copy (push)0fc6e977-cb12-44f6-b263-2824ba917409bash
137command-and-controlT1105Ingress Tool Transfer2rsync remote file copy (pull)3180f7d5-52c0-4493-9ea0-e3431a84773fbash
138command-and-controlT1105Ingress Tool Transfer3scp remote file copy (push)83a49600-222b-4866-80a0-37736ad29344bash
139command-and-controlT1105Ingress Tool Transfer4scp remote file copy (pull)b9d22b9a-9778-4426-abf0-568ea64e9c33bash
140command-and-controlT1105Ingress Tool Transfer5sftp remote file copy (push)f564c297-7978-4aa9-b37a-d90477feea4ebash
141command-and-controlT1105Ingress Tool Transfer6sftp remote file copy (pull)0139dba1-f391-405e-a4f5-f3989f2c88efbash
142command-and-controlT1090.001Internal Proxy1Connection Proxy0ac21132-4485-4212-a681-349e8a6637cdsh
143command-and-controlT1090.001Internal Proxy2Connection Proxy for macOS UI648d68c1-8bcd-4486-9abe-71c6655b6a2csh
144command-and-controlT1571Non-Standard Port2Testing usage of uncommonly used port5db21e1d-dd9c-4a50-b885-b1e748912767sh
145command-and-controlT1132.001Standard Encoding1Base64 Encoded data.1164f70f-9a88-4dff-b9ff-dc70e7bf0c25sh
146command-and-controlT1071.001Web Protocols3Malicious User Agents - Nix2d7c471a-e887-4b78-b0dc-b0df1f2e0658sh
147collectionT1560.001Archive via Utility5Data Compressed - nix - zipc51cec55-28dd-4ad2-9461-1eacbc82c3a0sh
148collectionT1560.001Archive via Utility6Data Compressed - nix - gzip Single Filecde3c2af-3485-49eb-9c1f-0ed60e9cc0afsh
149collectionT1560.001Archive via Utility7Data Compressed - nix - tar Folder or File7af2b51e-ad1c-498c-aca8-d3290c19535ash
150collectionT1560.001Archive via Utility8Data Encrypted with zip and gpg symmetric0286eb44-e7ce-41a0-b109-3da516e05a5fsh
151collectionT1115Clipboard Data3Execute commands from clipboard1ac2247f-65f8-4051-b51f-b0ccdfaaa5ffbash
152collectionT1056.002GUI Input Capture1AppleScript - Prompt User for Password76628574-0bc1-4646-8fe2-8f4427b47d15bash
153collectionT1074.001Local Data Staging2Stage data from Discovery.sh39ce0303-ae16-4b9e-bb5b-4f53e8262066bash
154collectionT1113Screen Capture1Screencapture0f47ceb1-720f-4275-96b8-21f0562217acbash
155collectionT1113Screen Capture2Screencapture (silent)deb7d358-5fbd-4dc4-aecc-ee0054d2d9a4bash
156exfiltrationT1030Data Transfer Size Limits1Data Transfer Size Limitsab936c51-10f4-46ce-9144-e02137b2016ash
157exfiltrationT1048Exfiltration Over Alternative Protocol1Exfiltration Over Alternative Protocol - SSHf6786cc8-beda-4915-a4d6-ac2f193bb988sh
158exfiltrationT1048Exfiltration Over Alternative Protocol2Exfiltration Over Alternative Protocol - SSH7c3cb337-35ae-4d06-bf03-3032ed2ec268sh
159exfiltrationT1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol1Exfiltration Over Alternative Protocol - HTTP1d1abbd6-a3d3-4b2e-bef5-c59293f46effmanual
160credential-accessT1552.003Bash History1Search Through Bash History3cfde62b-7c33-4b26-a61e-755d6131c8cesh
161credential-accessT1552.001Credentials In Files1Extract Browser and System credentials with LaZagne9e507bb8-1d30-4e3b-a49b-cb5727d7ea79bash
162credential-accessT1552.001Credentials In Files2Extract passwords with grepbd4cf0d1-7646-474e-8610-78ccf5a097c4sh
163credential-accessT1555.003Credentials from Web Browsers2Search macOS Safari Cookiesc1402f7b-67ca-43a8-b5f3-3143abedc01bsh
164credential-accessT1056.002GUI Input Capture1AppleScript - Prompt User for Password76628574-0bc1-4646-8fe2-8f4427b47d15bash
165credential-accessT1555.001Keychain1Keychain1864fdec-ff86-4452-8c30-f12507582a93sh
166credential-accessT1040Network Sniffing2Packet Capture macOS9d04efee-eff5-4240-b8d2-07792b873608bash
167credential-accessT1552.004Private Keys2Discover Private SSH Keys46959285-906d-40fa-9437-5a439accd878sh
168credential-accessT1552.004Private Keys4Copy Private SSH Keys with rsync864bb0b2-6bb5-489a-b43b-a77b3a16d68ash