T1548.006 · TCC Manipulation
Sub-técnica de T1548 · Abuse Elevation Control Mechanism.
Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions. TCC is a Privacy & Security macOS control mechanism used to determine if the running process has permission to access the data or services protected...
¿Cómo detectarlo y mitigarlo?
Técnicas relacionadas
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.002
Bypass User Account Control T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.