Compliance Node Overview
MITRE ATT&CK T1546.006 (LC_LOAD_DYLIB Addition) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries. Mach-O binaries have a series of headers that are used to perform certain operations when a binary is loaded. The LC_LOAD_DYLIB header in a Mach-O binary tells macOS and OS X which dynamic libraries (dylibs) to load during execution time. These can be added ad-hoc to the compiled binary as long as adjustments are made to the rest of the fields and dependencies. Affected platforms: macOS. MITRE-documented mitigations include M1047 Audit, M1038 Execution Prevention, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-06, CM-07, CM-08.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/006/
SHA-256 integrity: 56029b78fb8fe3b517b291f6db5f3e4e8dacec3180ef2fa35651e0089dde78f1
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1546.006: LC_LOAD_DYLIB Addition (https://attack.mitre.org/techniques/T1546/006/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.