Abuse Elevation Control Mechanism: TCC Manipulation T1548.006
Tactic: Privilege Escalation
Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions. TCC is a Privacy & Security macOS control mechanism used to determine if the running process has permission to access the data or services protected by TCC, such as screen sharing, camera, microphone, or Full Disk Access (FDA).
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| ESF | open | File Open |
Authoring guide
These 7 rules share fields, values, and exclusions.
Fields filtered most (19 distinct)
These fields appear most often in rule filters.
Top indicator values (45 distinct)
These values appear most often in rule predicates.
Exclusions (23 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint
Elastic 7 rules
- Full Disk Access Permission Check
- Potential Privacy Control Bypass via Localhost Secure Copy
- Potential Privacy Control Bypass via TCCDB Modification
- Potential Privilege Escalation via TCC bypass with fake TCC.db
- Suspicious TCC Access Granted for User Folders
- Tccutil Reset via Suspicious Binary
- User TCC DB Access by Osascript