用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill t1569-001-launchctl命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | T1569.001_launchctl |
| description | Adversaries may abuse launchctl to execute commands or programs. |
| category | input-validation |
| version | 18.1 |
| author | cyberstrike-official |
| tags | ["mitre-attack","enterprise","t1569.001","execution","macos","sub-technique"] |
| technique_id | T1569.001 |
| tactic | execution |
| all_tactics | ["execution"] |
| platforms | ["macOS"] |
| mitre_url | https://attack.mitre.org/techniques/T1569/001 |
| tech_stack | ["macos"] |
| cwe_ids | ["CWE-94"] |
| chains_with | ["T1569","T1569.002","T1569.003"] |
| prerequisites | ["T1569"] |
| severity_boost | {"T1569":"Chain with T1569 for deeper attack path","T1569.002":"Chain with T1569.002 for deeper attack path","T1569.003":"Chain with T1569.003 for deeper attack path"} |
Sub-technique of: T1569
Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input.
Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries can use scripts or manually run the commands launchctl load -w "%s/Library/LaunchAgents/%s" or /bin/launchctl load to execute Launch Agents or Launch Daemons.
Platforms: macOS
The following tests are from Atomic Red Team and provide actionable ways to test this technique:
Utilize launchctl
Supported Platforms: macos
launchctl submit -l #{label_name} -- #{executable_path}
If Atomic Red Team tests are not applicable, manually verify the technique by:
Identify Attack Surface: Determine if the target environment is susceptible to Launchctl by examining the target platforms (macOS).
Assess Existing Defenses: Review whether mitigations for T1569.001 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Prevent users from installing their own launch agents or launch daemons.
| Finding | Severity | Impact |
|---|---|---|
| Launchctl technique applicable | Low | Execution |
| CWE ID | Title |
|---|---|
| CWE-94 | Improper Control of Generation of Code |