Techniques
Sample rules
Suspicious Calendar File Modification
- source: elastic
- technicques:
- T1546
Description
Identifies suspicious modifications of the calendar file by an unusual process. Adversaries may create a custom calendar notification procedure to execute a malicious program at a recurring interval to establish persistence.
Detection logic
event.category:file and host.os.type:macos and event.action:modification and
file.path:/Users/*/Library/Calendars/*.calendar/Events/*.ics and
process.executable:
(* and not
(
/System/Library/* or
/System/Applications/Calendar.app/Contents/MacOS/* or
/System/Applications/Mail.app/Contents/MacOS/Mail or
/usr/libexec/xpcproxy or
/sbin/launchd or
/Applications/*
)
)