trash
trash is a built-in command-line utility that first appeared in macOS 15 (Sequoia). It takes one or more file or directory paths and moves each item into the current user's Trash folder (~/.Trash), the same result a user gets by choosing "Move to Trash" in the Finder. For an attacker it is an indicator-removal primitive: payloads, staging directories, and dropped files leave their original paths through a move (a rename on the same volume) rather than an unlink(2), so file-deletion telemetry and rules keyed on rm, unlink, or secure-erase tools such as srm or shred do not observe the activity. It is macOS-specific, relying on the user Trash folder semantics, and has no GTFOBins entry. Its evasion value is limited: trashed items stay fully recoverable in ~/.Trash until the Trash is emptied, and trash has no flag to empty the Trash, so it conceals a removal from deletion-focused detection without destroying the data.
Paths
/usr/bin/trash Example Use Cases
Move files and directories to the Trash without rm or unlink #
trash moves each named file or directory into ~/.Trash. On the same volume this is a rename rather than an unlink(2) of the original path, so endpoint rules and log-based monitoring keyed on rm, unlink, or secure-delete utilities do not fire when an artifact leaves its staging location. A directory is moved as a whole subtree in one call, replacing an rm -rf walk. The running account needs an existing ~/.Trash (present for a normal login user). Items land in the Trash and stay recoverable until it is emptied, so this hides the removal from deletion telemetry rather than destroying the data.
trash /private/tmp/stage.bin /Users/<USER>/Library/LaunchAgents/com.attacker.helper.plist /Users/<USER>/Library/Caches/.workdir Verify a scripted cleanup with --stopOnError #
The --stopOnError (-s) flag makes trash exit with an error if any item cannot be moved to the Trash, and --verbose (-v) reports each move. A cleanup or self-destruct routine uses these to confirm that every artifact was removed and to branch to a fallback if one could not be, without calling rm. The removed items still land in ~/.Trash and are recoverable until the Trash is emptied.
trash --stopOnError --verbose /private/tmp/impl /private/tmp/creds.json Detections
- Process execution: alert on /usr/bin/trash whose parent is a non-interactive or scripted process rather than an interactive user shell or the Finder, especially when its file arguments point at staging paths such as /tmp, /private/tmp, or /Users/*/Library/LaunchAgents
- Endpoint Security file telemetry: correlate rename events that move recently created files into a user's ~/.Trash by a process other than Finder; a create-then-trash sequence on the same path from a non-GUI process is anomalous