MacOS Native Tools Enable Stealthy Enterprise Attacks (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Attackers use macOS native tools like osascript and curl for attacks.
- Metadata abuse enables hidden command execution.
- LOTL techniques complicate detection by security software.
"Attackers increasingly use macOS native tools (living-off-the-land) to infiltrate enterprise networks. These methods abuse legitimate system tools and metadata to bypass security software. The article describes examples and countermeasures."
no comments yet.