T1569.001 Launchctl
Sub-technique of: T1569
High-Level Description
Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input.
Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries can use scripts or manually run the commands launchctl load -w "%s/Library/LaunchAgents/%s" or /bin/launchctl load to execute Launch Agents or Launch Daemons.
Kill Chain Phase
- Execution (TA0002)
Platforms: macOS
What to Check
- Identify if Launchctl technique is applicable to target environment
- Check macOS systems for indicators of Launchctl
- Verify mitigations are bypassed or absent (1 known mitigations)
- Assess detection coverage (1 detection strategies)
How to Test
Atomic Red Team Tests
The following tests are from Atomic Red Team and provide actionable ways to test this technique:
Atomic Test 1: Launchctl
Utilize launchctl
Supported Platforms: macos
launchctl submit -l #{label_name} -- #{executable_path}
Manual Testing
If Atomic Red Team tests are not applicable, manually verify the technique by:
Identify Attack Surface: Determine if the target environment is susceptible to Launchctl by examining the target platforms (macOS).
Assess Existing Defenses: Review whether mitigations for T1569.001 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Remediation Guide
M1018 User Account Management
Prevent users from installing their own launch agents or launch daemons.
Detection
Detection Strategy for System Services: Launchctl
Risk Assessment
| Finding | Severity | Impact |
|---|---|---|
| Launchctl technique applicable | Low | Execution |
CWE Categories
| CWE ID | Title |
|---|---|
| CWE-94 | Improper Control of Generation of Code |