// MITRE ATT&CK

T1548.006 · TCC Manipulation

🎯 Privilege Escalation macOS Sub-technique

Sub-technique of T1548 · Abuse Elevation Control Mechanism.

Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions. TCC is a Privacy & Security macOS control mechanism used to determine if the running process has permission to access the data or services protected...

How to detect & mitigate it

Detecting TCC Manipulation starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.