Event Triggered Execution: Emond T1546.014
Tactics: Privilege Escalation, Persistence
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond). Emond is a Launch Daemon that accepts events from various services, runs them through a simple rules engine, and takes action. The emond binary at /sbin/emond will load any rules from the /etc/emond.d/rules/ directory and take action once an explicitly defined event takes place.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | create | File or Directory Create |
| ESF | write | File Write |
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (6 distinct)
These fields appear most often in rule filters.
Top indicator values (37 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint