T1553.001sub-technique of T1553 Subvert Trust Controls
Gatekeeper Bypass
macOSnothing on this site yetT1553.001 on attack.mitre.org
Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Ransomware, suspected or confirmed
Files renamed or unreadable, a ransom note, or backup deletion commands seen.
how MITRE says to see it
Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
- Correlates suspicious removal or modification of the com.apple.quarantine extended attribute, manipulation of LSFileQuarantineEnabled values in Info.plist, and unexpected process execution of unsigned or non-notarized binaries.
what reduces it
- M1038 Execution Prevention. System settings can prevent applications from running that haven't been downloaded through the Apple Store which can help mitigate some of these issues.