← All Binaries

pmset

pmset manipulates system power management settings such as idle sleep timers, wake-on-network behavior, hibernation, and scheduled sleep/wake/power-on events. Reading settings and event history is unprivileged; modifying any setting requires root. All changes are persisted per-system (not per-user) in property lists under /Library/Preferences/SystemConfiguration/ (com.apple.PowerManagement.plist for settings, com.apple.AutoWake.plist for scheduled events), so they survive reboots without a launchd job or login item. It is attractive to an attacker for two reasons. First, its scheduled "wake" and "power on" events and its keep-awake settings let an operator guarantee that a laptop that would otherwise be asleep or shut down is running and reachable at a chosen time, giving a predictable window for command and control that lives outside the launchd/cron locations defenders normally inspect. Second, the read side (pmset -g log and -g assertions) exposes a detailed sleep/wake timeline and the processes currently holding the machine awake, which is a reliable proxy for whether a human is actively using the host.

Author: Hare Sudhan (@cyb3rbuff) Created: 2026-09-20

Paths

/usr/bin/pmset

Example Use Cases

Schedule a recurring wake or power-on for a command-and-control window #

Running as root, pmset can register a repeating "wakeorpoweron" event that wakes a sleeping Mac (or powers on a Mac that was shut down, on hardware that supports it) at a fixed time on chosen weekdays. This guarantees the host is running and network-reachable during the operator's chosen window without an implant having to keep the machine awake continuously. The schedule is stored in /Library/Preferences/SystemConfiguration/com.apple.AutoWake.plist rather than in a launchd job, so it does not appear alongside conventional persistence.

sudo pmset repeat wakeorpoweron MTWRFSU 03:00:00

Disable idle sleep to keep an implanted host awake and reachable #

As root, pmset can set the system, disk, and display idle-sleep timers to 0 (never) across all power sources. A value of 0 disables the timer entirely, so a laptop left on battery no longer sleeps and drops its network connection, keeping a long-running C2 channel or exfiltration session alive. Unlike caffeinate, which holds a transient assertion for the life of a process, this writes a persistent setting to com.apple.PowerManagement.plist that survives reboots and shows no owning process in the assertions list.

sudo pmset -a sleep 0 disksleep 0 displaysleep 0

Enable wake on network access for remote wake from the LAN #

As root, pmset can enable "womp" (wake on ethernet magic packet). Once set, an attacker positioned on the same broadcast domain can send a Wake-on-LAN magic packet to the target's MAC address to bring a sleeping Mac back online on demand, rather than waiting on a fixed schedule. The wake path brings the OS up behind the lock screen, so it is a network-reachability primitive, not an authentication bypass.

sudo pmset -a womp 1

Review sleep/wake history to infer when the host is unattended #

pmset -g log prints a timeline of sleeps, wakes, display-on/off transitions, and their causes, and requires no privileges. An operator can use it to infer when the host is actively used versus left unattended, informing the timing of hands-on-keyboard activity to avoid an active user noticing.

pmset -g log

List active power assertions to identify running applications #

pmset -g assertions lists the processes currently preventing idle or display sleep, without requiring root. This exposes which applications are actively running and holding the machine awake, complementing the sleep/wake timeline as a signal of user presence and workload.

pmset -g assertions

Retain the FileVault key across standby by disabling key destruction #

On a FileVault-encrypted Mac, destroyfvkeyonstandby controls whether the volume key is purged from memory when the system enters standby. Setting it to 0 (retain) as root keeps the key resident so the machine wakes without a password prompt, which both preserves seamless access for the attacker and keeps the key available in memory for a later extraction attempt. This weakens the at-rest protection FileVault provides during sleep.

sudo pmset -a destroyfvkeyonstandby 0

Detections

  • Command-line detection: pmset invoked with 'repeat' or 'schedule' and a wake/wakeorpoweron/poweron type, indicating a scheduled power event was created
  • Command-line detection: pmset setting sleep/disksleep/displaysleep to 0, or setting womp 1 or destroyfvkeyonstandby 0
  • File integrity monitoring: unexpected changes to /Library/Preferences/SystemConfiguration/com.apple.AutoWake.plist (scheduled events) or com.apple.PowerManagement.plist (power settings)

Resources