dsenableroot
dsenableroot is the command-line equivalent of Directory Utility's "Enable Root User" action. It writes a password onto the local root account and activates it, and -d disables it again. Administrator credentials can be passed with -u and -p, so the whole operation runs from a script with no interactive prompt. For an attacker who already holds admin credentials, it creates a second UID 0 account that is independent of the compromised user, so it survives that user's password reset or deletion. The Calisto trojan used it to enable the hidden root account with a hard-coded password alongside Remote Login and Screen Sharing.
Paths
/usr/sbin/dsenableroot Example Use Cases
Enable the root account non-interactively for persistent privileged access #
-u and -p supply administrator credentials and -r supplies the new root password, so the command runs unattended with no prompt. It needs valid admin credentials, and the resulting root account is independent of the admin account used to create it, so it survives that account's password reset or deletion.
dsenableroot -u <ADMIN_USER> -p <ADMIN_PASSWORD> -r <NEW_ROOT_PASSWORD> Enable the root account interactively to keep credentials out of the command line #
With no arguments, dsenableroot prompts for the caller's password and the new root password. Neither secret reaches argv, so they stay out of shell history and the process argument list, though the process name is still recorded. Requires an interactive TTY and an admin session.
dsenableroot Disable the root account to clean up after use #
-d removes the root account's password and disables it, restoring the default macOS state. An operator can enable root, use it, and disable it again, leaving the account state as it was before.
dsenableroot -d -u <ADMIN_USER> -p <ADMIN_PASSWORD> Detections
Resources
- Apple Support: How to enable the root user or change the root password on Mac
- dsenableroot man page
- MITRE ATT&CK T1078.003 Valid Accounts: Local Accounts
- Atomic Red Team T1078.003 - Enable root account using dsenableroot utility
- Kaspersky Securelist: Calisto Trojan for macOS
- CIS Apple macOS Benchmark 5.5 - Ensure the 'root' Account Is Disabled