TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

MacOS Native Tools Enable Stealthy Enterprise Attacks

2026-04-22 · Read original ↗

ATT&CK techniques detected

4 predictions
T1021.002SMB/Windows Admin Shares
97%
"a single command. the research also highlights multiple native protocols that can be used for lateral movement and file transfer : - server message block ( smb ) for mounting remote shares - netcat for direct command execution and file delivery - git repositories for pushing payl…"
T1059.002AppleScript
54%
"leveraging apple ' s inter - process communication ( ipc ) framework, attackers can issue instructions without triggering conventional shell - based monitoring. in some cases, adversaries bypass built - in restrictions by using terminal as a proxy for execution, encoding payloads…"
T1559Inter-Process Communication
53%
"leveraging apple ' s inter - process communication ( ipc ) framework, attackers can issue instructions without triggering conventional shell - based monitoring. in some cases, adversaries bypass built - in restrictions by using terminal as a proxy for execution, encoding payloads…"
T1204User Execution
34%
"macos native tools enable stealthy enterprise attacks a growing range of native macos features are being repurposed by attackers to execute code, move laterally and evade detection, according to new research examining " living - off - the - land " ( lotl ) techniques on apple sys…"

Summary

macOS LOTL techniques bypass detection using native tools and metadata abuse