Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or restarts via the macOS Graphical User Interface (GUI), a prompt is provided to the user with a checkbox to "Reopen windows when logging back in".(Citation: Re-Open windows on Mac) When selected, all applications currently open are added to a property list file named com.apple.loginwindow.[UUID].plist within the ~/Library/Preferences/ByHost directory.(Citation: Methods of Mac Malware Persistence)(Citation: Wardle Persistence Chapter) Applications listed in this file are automatically reopened upon the user’s next logon. Adversaries can establish [Persistence](https://attack.mitre.org/tactics/TA0003) by adding a malicious application path to the com.apple.loginwindow.[UUID].plist file to execute payloads when a user logs in.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Disable or Remove Feature or Program
is blocked by Detect persistence via reopened application plist modification (macOS)
is blocked by User Training
is blocked by Asset Inventories
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Access Enforcement
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch