Compliance Node Overview
MITRE ATT&CK T1543.004 (Launch Daemon) is an Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist files used to interact with Launchd, the service management framework used by macOS. Launch Daemons require elevated privileges to install, are executed for every user on a system prior to login, and run in the background without the need for user interaction. Affected platforms: macOS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-17, CA-07, CM-02, CM-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1543/004/
SHA-256 integrity: 767097fee8fb5af3d2ba13afb2a7068668f157286a1e26b0ff5947d40cc67a34
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1543.004: Launch Daemon (https://attack.mitre.org/techniques/T1543/004/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access