What MITRE ATT&CK T1569.001: Launchctl (Enterprise Tactic TA0002 - Execution) requires
MITRE ATT&CK T1569.001 (Launchctl) is an Enterprise Execution sub-technique of T1569 (System Services). Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input. Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Affected platforms: macOS. MITRE-documented mitigations include M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1569/001/
SHA-256 integrity: b46b764334fc69a32261076465c8cdb974bc0611b8e5429756bd98f01f4a7002
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1569.001: Launchctl (https://attack.mitre.org/techniques/T1569/001/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1569-001-launchctl.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1569-001-launchctl.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1569-001-launchctl
- Back to registry: Browse all 10,085 compliance nodes