Compliance Node Overview
MITRE ATT&CK T1548.006 (TCC Manipulation) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions. TCC is a Privacy & Security macOS control mechanism used to determine if the running process has permission to access the data or services protected by TCC, such as screen sharing, camera, microphone, or Full Disk Access (FDA). Affected platforms: macOS. MITRE-documented mitigations include M1026 Privileged Account Management, M1047 Audit, M1022 Restrict File and Directory Permissions, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, CA-07, CM-02, CM-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1548/006/
SHA-256 integrity: 6a2316adf7f064b04144121878d8b790a7b56fead954217df700eabf27330e0c
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1548.006: TCC Manipulation (https://attack.mitre.org/techniques/T1548/006/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access