← All Binaries

trash

trash is a built-in command-line utility that first appeared in macOS 15 (Sequoia). It takes one or more file or directory paths and moves each item into the current user's Trash folder (~/.Trash), the same result a user gets by choosing "Move to Trash" in the Finder. For an attacker it is an indicator-removal primitive: payloads, staging directories, and dropped files leave their original paths through a move (a rename on the same volume) rather than an unlink(2), so file-deletion telemetry and rules keyed on rm, unlink, or secure-erase tools such as srm or shred do not observe the activity. It is macOS-specific, relying on the user Trash folder semantics, and has no GTFOBins entry. Its evasion value is limited: trashed items stay fully recoverable in ~/.Trash until the Trash is emptied, and trash has no flag to empty the Trash, so it conceals a removal from deletion-focused detection without destroying the data.

Author: Hare Sudhan (@cyb3rbuff) Created: 2026-09-20

Paths

/usr/bin/trash

Example Use Cases

Verify a scripted cleanup with --stopOnError #

The --stopOnError (-s) flag makes trash exit with an error if any item cannot be moved to the Trash, and --verbose (-v) reports each move. A cleanup or self-destruct routine uses these to confirm that every artifact was removed and to branch to a fallback if one could not be, without calling rm. The removed items still land in ~/.Trash and are recoverable until the Trash is emptied.

trash --stopOnError --verbose /private/tmp/impl /private/tmp/creds.json

Detections

  • Process execution: alert on /usr/bin/trash whose parent is a non-interactive or scripted process rather than an interactive user shell or the Finder, especially when its file arguments point at staging paths such as /tmp, /private/tmp, or /Users/*/Library/LaunchAgents
  • Endpoint Security file telemetry: correlate rename events that move recently created files into a user's ~/.Trash by a process other than Finder; a create-then-trash sequence on the same path from a non-GUI process is anomalous

Resources