Subvert Trust Controls: Gatekeeper Bypass T1553.001
Tactic: Defense Impairment
Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper also treats applications running for the first time differently than reopened applications.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
Authoring guide
These 13 rules share fields, values, and exclusions.
Fields filtered most (17 distinct)
These fields appear most often in rule filters.
Top indicator values (79 distinct)
These values appear most often in rule predicates.
Exclusions (51 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint
Sigma 2 rules
Elastic 10 rules
- Attempt to Disable Gatekeeper
- Gatekeeper Override and Execution
- Potential Payload Download via AppleScript Applet
- Quarantine Attrib Removed by Unsigned or Untrusted Process
- Quarantine Attribute Deleted via Untrusted Binary
- Quarantine Attribute Removal via TextEdit
- Quarantine Cleared via Xattr Followed by Ad-hoc Codesign
- Suspicious Curl from macOS Application
- Suspicious File Quarantine Removal via Find
- Suspicious Outbound Network Connection via Unsigned Binary