kickstart
kickstart is a Perl script inside the Apple Remote Desktop agent bundle (/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart), Apple's supported way to install, activate, configure and restart the Remote Management service without a reboot, documented in Apple article 101439. Running as root, it loads the com.apple.screensharing LaunchDaemon, enables the service, sets per-user ARD privileges through dscl, and writes client settings to the RemoteManagement and RemoteDesktop plists. For an attacker with root, this Apple-signed script turns a host into a controllable screen-sharing and remote-command endpoint (TCP 5900 and 3283) with nothing dropped on disk, and can grant access to a chosen account, set a legacy VNC password, hide the menu bar indicator and later strip the configuration. Mandiant observed attackers connecting over SSH, running kickstart to enable Remote Desktop, then moving laterally over the screen-sharing channel. On macOS 10.14 and later it checks TCC state and warns that screen recording or control may still be blocked, so activation alone does not guarantee a usable screen unless the ARDAgent already holds the relevant TCC grants.
Paths
/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart Example Use Cases
Activate Remote Management and grant every local user full control #
The -activate option loads the com.apple.screensharing LaunchDaemon and enables the service, and -configure -allowAccessFor -allUsers -privs -all sets ARD_AllLocalUsers and the all-user privilege mask so any local account can log in with full control. Mandiant observed this command after attackers connected over SSH. Requires root; on macOS 10.14 and later the ARDAgent additionally needs Screen Recording and Accessibility TCC grants for screen control to work.
sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -allowAccessFor -allUsers -privs -all -quiet
Grant ARD access to a single attacker-controlled account #
Instead of flipping the all-users switch, -configure -access -on -privs -all -users <USERNAME> sets the "naprivs" bitmask on just the named local user record via dscl. System Settings then shows access limited to specified users, which resembles a normal administrative configuration and leaves fewer accounts changed. Requires root and an existing local account with a UID above 500.
sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -configure -access -on -privs -all -users <USERNAME>
Enable legacy VNC authentication with an attacker-chosen password #
-configure -clientopts -setvnclegacy -vnclegacy yes -setvncpw -vncpw <PASSWORD> turns on legacy VNC password mode and stores the password in /Library/Preferences/com.apple.VNCSettings.txt. This authentication path does not depend on any macOS account password, so it survives a password reset and is reachable from any standard VNC client. kickstart obfuscates the stored password with a fixed XOR key, so the file is trivially reversible by anyone who can read it, and the service truncates the password to 8 characters with no rate limiting, making brute force practical. Requires root.
sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -configure -clientopts -setvnclegacy -vnclegacy yes -setvncpw -vncpw <PASSWORD>
Escalate a headless SSH foothold to an interactive desktop session #
A shell obtained over SSH cannot answer GUI-only prompts such as TCC consent dialogs, keychain unlock requests or authorization sheets. Activating Remote Management over the SSH session and restarting the agent gives a screen-sharing channel into the console user's live session, where those dialogs can be clicked through as the logged-in user and the desktop and typed content observed. Requires root over SSH, an interactive console session, and on macOS 10.14 and later the Screen Recording and Accessibility TCC grants for the ARDAgent.
ssh <USER>@<TARGET_IP> "sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -on -privs -all -users <USERNAME> -restart -agent -console"
Deactivate the service and strip the access privileges after use #
-deactivate unloads the com.apple.screensharing LaunchDaemon, kills the screen sharing daemon and agent, and deletes the RemoteManagement.launchd marker file. -uninstall -settings additionally deletes com.apple.RemoteDesktop.plist, com.apple.ARDAgent.plist and com.apple.RemoteManagement.plist, and destroys the "naprivs" attribute on every local user record. An attacker uses this to remove the configuration once the objective is met. Requires root.
sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -uninstall -settings -deactivate -stop -quiet
Detections
Resources
- Use the kickstart command-line utility in Apple Remote Desktop - Apple Support
- Living off the Orchard: Leveraging Apple Remote Desktop for Good and Evil - Mandiant
- MacOS Red Teaming 206: ARD (Apple Remote Desktop Protocol) - LockBoxx
- MITRE ATT&CK T1021.005 - Remote Services: VNC
- Atomic Red Team T1021.005 - Apple Remote Desktop activation via kickstart, usable as a detection test case
- ARDvark - Mandiant parser for Apple Remote Desktop forensic artifacts
- kickstart command reference - ss64
Acknowledgements
- Jake Nicastro and Willi Ballenthin (Mandiant) for documenting kickstart-enabled Apple Remote Desktop lateral movement and the associated forensic artifacts
- Dan Borges (LockBoxx) for the ARD red teaming research covering legacy VNC password weaknesses and screen sharing tradecraft