Compliance Node Overview
MITRE ATT&CK T1553.001 (Gatekeeper Bypass) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple's security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Affected platforms: macOS. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1553/001/
SHA-256 integrity: c290b7fba7ae3b24b8a81c28861fc70d08e09a56ec007783b838019cdec8deec
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1553.001: Gatekeeper Bypass (https://attack.mitre.org/techniques/T1553/001/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access