Persistence via a Hidden Plist Filename
Identifies the creation of a hidden launch agent or daemon property list file. An adversary may establish persistence by installing a new launch agent or daemon which executes at login. Hidden plist files with filenames starting with a dot are particularly suspicious.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/01/30"
3integration = ["endpoint"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies the creation of a hidden launch agent or daemon property list file. An adversary may establish
11persistence by installing a new launch agent or daemon which executes at login. Hidden plist files with
12filenames starting with a dot are particularly suspicious.
13"""
14from = "now-9m"
15index = ["logs-endpoint.events.file-*"]
16language = "eql"
17license = "Elastic License v2"
18name = "Persistence via a Hidden Plist Filename"
19references = [
20 "https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/",
21 "https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/CreatingLaunchdJobs.html"
22]
23risk_score = 73
24rule_id = "e3f5a566-df31-40cc-987c-24bc4bb94ba5"
25severity = "high"
26tags = [
27 "Domain: Endpoint",
28 "OS: macOS",
29 "Use Case: Threat Detection",
30 "Tactic: Persistence",
31 "Tactic: Defense Evasion",
32 "Data Source: Elastic Defend",
33 "Resources: Investigation Guide",
34 "Noise: Low",
35 "Performance: Fast",
36 "Profile: Recommended",
37 "Rule Type: Event Correlation (EQL)",
38 "Platform: macOS",
39]
40timestamp_override = "event.ingested"
41type = "eql"
42note = """## Triage and analysis
43
44> **Disclaimer**:
45> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.
46
47### Investigating Persistence via a Hidden Plist Filename
48
49LaunchAgents and LaunchDaemons are macOS persistence mechanisms that automatically execute programs at login or system startup. Files with names starting with a dot (.) are hidden from standard directory listings in macOS, making them less visible to users and administrators. Threat actors combine these techniques by creating hidden plist files in LaunchAgent/LaunchDaemon directories to establish stealthy persistence that survives reboots while evading casual inspection. This behavior was notably observed in the CloudMensis macOS spyware campaign.
50
51### Possible investigation steps
52
53- Examine the file.path to identify the full path of the hidden plist file and determine whether it is in a user-specific or system-wide LaunchAgent/LaunchDaemon directory.
54- Use plutil or defaults to read the plist contents and identify the executable path, arguments, and execution conditions configured in the ProgramArguments or Program keys.
55- Locate the binary or script referenced in the plist file and calculate its hash for threat intelligence lookups.
56- Analyze the binary's code signature using codesign -dvvv to determine if it is signed, and by whom.
57- Review the process.executable that created the plist file to understand the initial delivery mechanism.
58- Check file creation timestamps to determine when the hidden plist was created and correlate with other security events.
59- Search for other hidden files in LaunchAgent and LaunchDaemon directories across the system.
60
61### False positive analysis
62
63- Chef configuration management may create hidden plists matching .chef-com* patterns. These are already excluded in the query.
64- Some legitimate applications may temporarily create dot-prefixed files during installation. Verify the process that created the file and its signature.
65- Backup and synchronization tools occasionally create hidden configuration files. Confirm the tool's legitimacy and expected behavior.
66- System processes like sed may create temporary hidden files during in-place editing operations. These are partially excluded in the query.
67
68### Response and remediation
69
70- Immediately unload the hidden LaunchAgent or LaunchDaemon using launchctl unload with the plist path.
71- Remove the hidden plist file from the LaunchAgent or LaunchDaemon directory.
72- Locate and remove the malicious binary or script referenced in the plist's Program or ProgramArguments keys.
73- Search for related hidden files, configuration files, or staging directories that may be part of the same malware deployment.
74- Review system logs for evidence of the hidden persistence mechanism executing and what actions it performed.
75- Check for data exfiltration or command and control communication if the behavior matches known spyware patterns like CloudMensis.
76- Reset credentials that may have been accessed while the persistence mechanism was active.
77- Monitor for recreation of hidden plist files in LaunchAgent and LaunchDaemon directories.
78"""
79query = '''
80file where host.os.type == "macos" and event.type != "deletion" and
81 file.path like~ (
82 "/System/Library/LaunchAgents/.*.plist",
83 "/Library/LaunchAgents/.*.plist",
84 "/Users/*/Library/LaunchAgents/.*.plist",
85 "/System/Library/LaunchDaemons/.*.plist",
86 "/Library/LaunchDaemons/.*.plist"
87 ) and
88 not (file.name like ".chef-com*.plist" and process.executable like "/opt/chef/embedded/bin/ruby") and
89 not (process.executable in ("/usr/bin/sed", "/bin/bash") and file.name like ".!*!*.plist")
90'''
91
92[[rule.threat]]
93framework = "MITRE ATT&CK"
94
95 [rule.threat.tactic]
96 name = "Persistence"
97 id = "TA0003"
98 reference = "https://attack.mitre.org/tactics/TA0003/"
99
100 [[rule.threat.technique]]
101 name = "Boot or Logon Autostart Execution"
102 id = "T1547"
103 reference = "https://attack.mitre.org/techniques/T1547/"
104
105 [[rule.threat.technique.subtechnique]]
106 name = "Plist Modification"
107 id = "T1547.011"
108 reference = "https://attack.mitre.org/techniques/T1547/011/"
109
110 [[rule.threat.technique]]
111 name = "Create or Modify System Process"
112 id = "T1543"
113 reference = "https://attack.mitre.org/techniques/T1543/"
114
115 [[rule.threat.technique.subtechnique]]
116 name = "Launch Agent"
117 id = "T1543.001"
118 reference = "https://attack.mitre.org/techniques/T1543/001/"
119
120[[rule.threat]]
121framework = "MITRE ATT&CK"
122
123 [rule.threat.tactic]
124 name = "Defense Evasion"
125 id = "TA0005"
126 reference = "https://attack.mitre.org/tactics/TA0005/"
127
128 [[rule.threat.technique]]
129 name = "Hide Artifacts"
130 id = "T1564"
131 reference = "https://attack.mitre.org/techniques/T1564/"
132
133 [[rule.threat.technique.subtechnique]]
134 name = "Hidden Files and Directories"
135 id = "T1564.001"
136 reference = "https://attack.mitre.org/techniques/T1564/001/"
Triage and analysis
Disclaimer: This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.
Investigating Persistence via a Hidden Plist Filename
LaunchAgents and LaunchDaemons are macOS persistence mechanisms that automatically execute programs at login or system startup. Files with names starting with a dot (.) are hidden from standard directory listings in macOS, making them less visible to users and administrators. Threat actors combine these techniques by creating hidden plist files in LaunchAgent/LaunchDaemon directories to establish stealthy persistence that survives reboots while evading casual inspection. This behavior was notably observed in the CloudMensis macOS spyware campaign.
Possible investigation steps
- Examine the file.path to identify the full path of the hidden plist file and determine whether it is in a user-specific or system-wide LaunchAgent/LaunchDaemon directory.
- Use plutil or defaults to read the plist contents and identify the executable path, arguments, and execution conditions configured in the ProgramArguments or Program keys.
- Locate the binary or script referenced in the plist file and calculate its hash for threat intelligence lookups.
- Analyze the binary's code signature using codesign -dvvv to determine if it is signed, and by whom.
- Review the process.executable that created the plist file to understand the initial delivery mechanism.
- Check file creation timestamps to determine when the hidden plist was created and correlate with other security events.
- Search for other hidden files in LaunchAgent and LaunchDaemon directories across the system.
False positive analysis
- Chef configuration management may create hidden plists matching .chef-com* patterns. These are already excluded in the query.
- Some legitimate applications may temporarily create dot-prefixed files during installation. Verify the process that created the file and its signature.
- Backup and synchronization tools occasionally create hidden configuration files. Confirm the tool's legitimacy and expected behavior.
- System processes like sed may create temporary hidden files during in-place editing operations. These are partially excluded in the query.
Response and remediation
- Immediately unload the hidden LaunchAgent or LaunchDaemon using launchctl unload with the plist path.
- Remove the hidden plist file from the LaunchAgent or LaunchDaemon directory.
- Locate and remove the malicious binary or script referenced in the plist's Program or ProgramArguments keys.
- Search for related hidden files, configuration files, or staging directories that may be part of the same malware deployment.
- Review system logs for evidence of the hidden persistence mechanism executing and what actions it performed.
- Check for data exfiltration or command and control communication if the behavior matches known spyware patterns like CloudMensis.
- Reset credentials that may have been accessed while the persistence mechanism was active.
- Monitor for recreation of hidden plist files in LaunchAgent and LaunchDaemon directories.
References
Related rules
- Apple Script Execution followed by Network Connection
- Creation of Hidden Launch Agent or Daemon
- Creation of Hidden Login Item via Apple Script
- Curl Execution via Shell Profile
- Dylib Injection via Process Environment Variables