Skip to main content

macos-post-exploitation

macOS endpoint post-exploitation — launchd persistence, TCC bypass, Keychain credential access, dylib hijacking, Gatekeeper/quarantine evasion, and discovery on Apple hosts.

Ir a la instalación

Datos de origen

Repositorio
BitterSecurity/Decepticon
Última actividad en el origen
30 de mayo de 2026 a las 01:17
Idioma detectado de SKILL.md
inglés
Estrellas
5565
Forks
1053

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
name
macos-post-exploitation
description
macOS endpoint post-exploitation — launchd persistence, TCC bypass, Keychain credential access, dylib hijacking, Gatekeeper/quarantine evasion, and discovery on Apple hosts.
allowed-tools
Bash Read Write
metadata
{"subdomain":"post-exploitation","when_to_use":"macOS, mac, osx, apple, launchd, LaunchAgent, LaunchDaemon, TCC, keychain, dylib hijack, Gatekeeper, quarantine, xattr, codesign, dscl, jamf, mdm","tags":"macos, osx, persistence, tcc, keychain, dylib, gatekeeper, launchd, privesc, credential-access","mitre_attack":"T1543.001, T1543.004, T1547.011, T1574.004, T1547.015, T1555.001, T1059.002, T1553.001, T1222.002, T1087.001, T1518, T1647"}
# macOS post-exploitation Post-compromise operations on Apple/macOS endpoints. Apple's controls (TCC, Gatekeeper/quarantine, SIP, code signing, AMFI) shape every step, so the playbook is organized around defeating or living within them. Prefer on-host built-ins (`launchctl`, `security`, `sqlite3`, `dscl`, `system_profiler`, `codesign`, `xattr`) over dropped tooling for OPSEC. > Authorized engagements only. Stay within RoE scope; emulate destructive > actions as benign proofs unless explicitly authorized. ## Discovery (T1087.001 / T1518 / T1647) - `system_profiler SPSoftwareDataType SPHardwareDataType` — OS build, model, SIP. - `csrutil status` — System Integrity Protection on/off. - `dscl . -list /Users | grep -v '^_'` — local accounts; `id`, `groups`. - `sw_vers`, `profiles status -type enrollment` — MDM/Jamf managed? (T1647 plist prefs). - Installed security tooling: `ls /Library/Objective-See`, `pgrep -l 'CrowdStrike|SentinelOne|falcon|Jamf|santad'`. ## Privilege escalation - **TCC bypass / abuse (T1548 family).** TCC gates access to Documents, Desktop, Downloads, camera/mic, Full Disk Access. Check `sqlite3 ~/Library/Application\ Support/com.apple.TCC/TCC.db 'select * from access'` (user) and `/Library/Application Support/com.apple.TCC/TCC.db` (system, needs root). Abuse an already-FDA-granted app (e.g. a terminal/Electron app) to read protected data instead of triggering a prompt. - **Sudo / admin group.** `sudo -n true` (cached creds), membership in `admin`. - **Setuid hunting:** `find / -perm -4000 -type f 2>/dev/null`. ## Persistence - **LaunchAgents / LaunchDaemons (T1543.001 / T1543.004).** Drop a plist in `~/Library/LaunchAgents` (user, no root) or `/Library/LaunchDaemons` (root, runs as root at boot); `launchctl bootstrap gui/$(id -u) <plist>`. The classic, noisy-but-reliable mechanism. - **Login items (T1547.015)** via `osascript -e 'tell application "System Events" to make login item ...'` or a Service Management (`SMAppService`) helper. - **Dylib hijacking / proxying (T1574.004).** Find apps with a writable/missing `@rpath` or weak-linked dylib (`otool -l <app>`); plant a malicious dylib that re-exports the original. Survives as the host app's identity. - **Re-opened apps / cron / emond / at** — lower-signal fallbacks. ## Defense evasion - **Gatekeeper / quarantine (T1553.001).** Downloaded files carry the `com.apple.quarantine` xattr; `xattr -d com.apple.quarantine <file>` (or `xattr -c`) strips it so the binary runs without the Gatekeeper prompt. - **Code signing (T1553).** `codesign --force --deep --sign - <bundle>` ad-hoc signs a tampered bundle; check `codesign -dv --verbose=4` and `spctl -a -vv`. - **File-permission/attribute manipulation (T1222.002):** `chflags`, `chmod`. - **AppleScript / osascript execution (T1059.002)** for living-off-the-land. ## Credential access (T1555.001) - **Keychain.** `security find-generic-password -ga <svc>` / `security find-internet-password`; `security dump-keychain -d ~/Library/Keychains/login.keychain-db` (prompts unless unlocked). Offline: exfil the `*.keychain-db` + the login password and crack with `chainbreaker`. - **Browser & app secrets** under `~/Library/Application Support/...` (often TCC-protected — see TCC abuse above). - **Sudo/SSH keys** in `~/.ssh`, `~/.aws`, `~/.kube`. ## Collection, C2 & exfil - Stage under `/tmp` or `~/Library/Caches`; archive with `tar`/`ditto`. - C2: prefer signed, allow-listed channels; see `post-exploit/c2` and `post-exploit/c2-sliver` (Sliver has a macOS implant). Beacon over HTTPS to blend with managed-device telemetry. ## Detection & defense (blue-cell notes) - Monitor new plists in `*/LaunchAgents` and `*/LaunchDaemons` and `launchctl` bootstraps; alert on `xattr -d com.apple.quarantine`, ad-hoc `codesign`, `security dump-keychain`, and TCC.db reads by non-Apple binaries. - Endpoint Security framework (ES) + tools like santad/Objective-See catch most of the above; LOTL via `osascript`/`launchctl` is the gap to watch. ## See also `post-exploit/credential-access`, `post-exploit/lateral-movement`, `post-exploit/privilege-escalation`, `shared/defense-evasion`, `reverser/ios-static`.
Ver en GitHub