credential_access_access_to_browser_credentials_procargs.toml
credential_access_credentials_keychains.toml
credential_access_dumping_hashes_bi_cmds.toml
credential_access_dumping_keychain_security.toml
credential_access_kerberosdump_kcc.toml
credential_access_keychain_pwd_retrieval_security_cmd.toml
credential_access_mitm_localhost_webproxy.toml
credential_access_potential_macos_ssh_bruteforce.toml
credential_access_promt_for_pwd_via_osascript.toml
credential_access_systemkey_dumping.toml
defense_evasion_apple_softupdates_modification.toml
defense_evasion_attempt_del_quarantine_attrib.toml
defense_evasion_attempt_to_disable_gatekeeper.toml
defense_evasion_install_root_certificate.toml
defense_evasion_modify_environment_launchctl.toml
defense_evasion_privacy_controls_tcc_database_modification.toml
defense_evasion_privilege_escalation_privacy_pref_sshd_fulldiskaccess.toml
defense_evasion_safari_config_change.toml
defense_evasion_sandboxed_office_app_suspicious_zip_file.toml
defense_evasion_tcc_bypass_mounted_apfs_access.toml
defense_evasion_unload_endpointsecurity_kext.toml
discovery_users_domain_built_in_commands.toml
execution_defense_evasion_electron_app_childproc_node_js.toml
execution_initial_access_suspicious_browser_childproc.toml
execution_installer_package_spawned_network_event.toml
execution_script_via_automator_workflows.toml
execution_scripting_osascript_exec_followed_by_netcon.toml
execution_shell_execution_via_apple_scripting.toml
initial_access_suspicious_mac_ms_office_child_process.toml
lateral_movement_credential_access_kerberos_bifrostconsole.toml
lateral_movement_mounting_smb_share.toml
lateral_movement_remote_ssh_login_enabled.toml
lateral_movement_vpn_connection_attempt.toml
persistence_account_creation_hide_at_logon.toml
persistence_creation_change_launch_agents_file.toml
persistence_creation_hidden_login_item_osascript.toml
persistence_creation_modif_launch_deamon_sequence.toml
persistence_credential_access_authorization_plugin_creation.toml
persistence_crontab_creation.toml
persistence_defense_evasion_hidden_launch_agent_deamon_logonitem_process.toml
persistence_directory_services_plugins_modification.toml
persistence_docker_shortcuts_plist_modification.toml
persistence_emond_rules_file_creation.toml
persistence_emond_rules_process_execution.toml
persistence_enable_root_account.toml
persistence_evasion_hidden_launch_agent_deamon_creation.toml
persistence_finder_sync_plugin_pluginkit.toml
persistence_folder_action_scripts_runtime.toml
persistence_login_logout_hooks_defaults.toml
persistence_loginwindow_plist_modification.toml
persistence_modification_sublime_app_plugin_or_script.toml
persistence_periodic_tasks_file_mdofiy.toml
persistence_screensaver_engine_unexpected_child_process.toml
persistence_screensaver_plist_file_modification.toml
persistence_suspicious_calendar_modification.toml
persistence_via_atom_init_file_modification.toml
privilege_escalation_applescript_with_admin_privs.toml
privilege_escalation_explicit_creds_via_scripting.toml
privilege_escalation_exploit_adobe_acrobat_updater.toml
privilege_escalation_local_user_added_to_admin.toml
privilege_escalation_root_crontab_filemod.toml
Folders and files Name Name Last commit message
Last commit date
parent directory
View all files
You can’t perform that action at this time.