Quarantine Attribute Deleted via Untrusted Binary
Description
Identifies a potential Gatekeeper bypass from an unsigned or untrusted binary. In macOS, when applications or programs are downloaded from the internet, there is a quarantine flag set on the file. This attribute is read by Apple's Gatekeeper defense program at execution time. An adversary may disable this attribute to evade defenses.
Query · eql
sequence with maxspan=1m
[process where event.action == "exec" and
(process.code_signature.trusted == false or process.code_signature.exists == false) and
not process.hash.sha256 == "2d3aa19d6f012c1a4ebc5907a05b06cf0d43a1499107020f59847ea2638c8649" and
not process.executable like "/opt/homebrew/*"] by process.entity_id
[process where event.action == "exec" and
process.args like~ "*xattr" and
process.name like~ ("bash", "sh", "zsh", "xattr", "python*", "osascript") and
(
(process.args like "com.apple.quarantine" and process.args like~ ("-d", "-w", "-?d", "-?w")) or
(process.args == "-c" and not process.args like "github.com/pkg/xattr")
)
] by process.parent.entity_id