Subvert Trust Controls: Gatekeeper Bypass T1553.001

Tactic: Defense Impairment

Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper also treats applications running for the first time differently than reopened applications.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution

Authoring guide

These 13 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType9eq 9exec, extended_attributes_delete, gatekeeper_override, gatekeeper_user_override
process_name7eq 4, in 2, wildcard 1curl, nscurl, bash, codesign, find
event.type6eq 5, in 1start, process_started
host.os.type5eq 5
process.args5eq 3, in 3, contains 1, ends_with 1, regex_match 1--deep, --directory, --download, --force, --master-disable
Image3ends_with 1, eq 1, is_not_null 1/usr/bin/xattr, /xattr
process.code_signature.exists3eq 3false
process.code_signature.trusted3eq 3false
CommandLine2contains 2com.apple.quarantine, -d, master-disable, spctl
parent_process_name2eq 1, wildcard 1applet, bash, osascript, python*
process.args_count2eq 1, le 11, 10
DestinationHostname1is_null 1
DestinationPort1lt 149152
TargetFilename1wildcard 1/applications/*, /private/tmp/*, /private/var/tmp/*
esf.event_type1eq 1146

Top indicator values (79 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
exec
5579
EventTypeeq
extended_attributes_delete
33
EventTypeeq
gatekeeper_override
1
EventTypeeq
gatekeeper_user_override
1
event.typeeq
start
51087
process.code_signature.existseq
false
3119
process.code_signature.trustedeq
false
3115
CommandLinecontains
com.apple.quarantine
22
CommandLinecontains
-d
18
CommandLinecontains
master-disable
1
CommandLinecontains
spctl
1
CommandLinecontains
xattr
1
process.argseq
-c
2107
process.argseq
-d
212
process.argseq
com.apple.quarantine
23
process_namein
curl
290
process_namein
nscurl
241
DestinationPortlt
49152
12
Imageends_with
/xattr
12
Imageeq
/usr/bin/xattr
1
TargetFilenamewildcard
/applications/*
1
TargetFilenamewildcard
/private/tmp/*
16
TargetFilenamewildcard
/private/var/tmp/*
12
TargetFilenamewildcard
/tmp/*
112
TargetFilenamewildcard
/users/*/applications/*
1
TargetFilenamewildcard
/users/*/desktop/*
1
TargetFilenamewildcard
/users/*/documents/*
1
TargetFilenamewildcard
/users/*/downloads/*
1
TargetFilenamewildcard
/users/shared/*
17
TargetFilenamewildcard
/var/tmp/*
19

Exclusions (51 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagestarts_with
/opt/homebrew/
2
DestinationPortin
22
1
DestinationPortin
25
1
DestinationPortin
443
1
DestinationPortin
465
1
DestinationPortin
53
1
DestinationPortin
587
1
DestinationPortin
80
1
DestinationPortin
8080
1
DestinationPortin
8200
1
DestinationPortin
9200
1
DestinationPortin
993
1
Hasheseq
2d3aa19d6f012c1a4ebc5907a05b06cf0d43a1499107020f59847ea2638c8649
1
Imagewildcard
/applications/.com.bomgar.scc.*/remote support customer...
1
Imagewildcard
/applications/cewe fotoschau.app/contents/macos/fotoplus
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: macOS

Domain: Endpoint

Sigma 2 rules

Elastic 10 rules

Splunk 1 rule