← All Tactics

Discovery

28 binaries with this tactic

csrutil

Configure or view system security policies.

Defense EvasionReconnaissanceDiscovery usersconfiguration

defaults

Read, write, and delete user preference values.

Defense EvasionDiscoveryPersistence gatekeeperfirewall

dns-sd

Discover local network services using the DNS-Based Service Discovery (SD) protocol.

Discovery network

dscacheutil

gather information, statistics and initiate queries to the Directory Service cache.

Discovery bashzsh

dscl

Interact with Directory Services.

DiscoveryPersistence usersnetworkconfiguration +4

dsconfigad

retrieves/changes configuration for Directory Services Active Directory Plugin.

Discovery bashzsh

dsexport

Export data from an Open Directory directory services server.

ReconnaissanceDiscovery ldapusersgroups

GetFileInfo

Get attributes of files and directories.

Discovery bashzshoneliner

ioreg

Displays a hierarchial view of the I/O Kit registry.

DiscoveryCollection bashonelinerlockscreen +1

kextstat

Display the status of loaded kernel extensions (kexts)

Discovery bashzshkernel

last

Show last user logins and TTYs.

Discovery onelineraccountnetwork

lsregister

Interact with the macOS Launch Services database.

DiscoveryImpact

mdfind

Locate files using the Spotlight database.

ReconnaissanceDiscoveryDefense Evasion bashzshoneliner +2

mdls

List metadata attributes for the specified file.

Defense EvasionDiscoveryExecution +1 genieoshlayercleanmaster +4

networksetup

Configure network settings in System Preferences.

DiscoveryCommand and Control networkconfigurationdns +1

notifyutil

Monitor and post Darwin notifications for inter-process communication and system event monitoring.

DiscoveryCollectionCommand and Control +2 monitoringsurveillancesystem-events +10

nvram

Access and manage the host's non-volatile random-access memory (NVRAM).

Discovery

odutil

odutil allows caller to examine or change state of opendirectoryd

Discovery bashzsh

osascript

Execute AppleScripts and other OSA language scripts and commands.

CollectionCredential AccessDiscovery +4 clipboardbashoneliner +15

profiles

List and remove configuration profiles.

DiscoveryImpact oneliner

say

Convert text to audible speech.

Defense EvasionCollectionReconnaissance +1 bashpbpasteclipboard +1

scutil

Display basic network information, check the dns config, set the computer hostname and perform several other tasks.

Discovery networkconfiguration

sfltool

Binary to manage the Shared File List framework.

DiscoveryDefense Evasion bashstartupsystem-reset

softwareupdate

Interact with the macOS software update service.

Discovery system-info

sqlite3

Query and manage sqlite databases.

DiscoveryCollectionCredential Access permissionsonelinercookie-theft

sw_vers

Prints macOS version information.

Discovery bashconfiguration

sysctl

Get macOS hardware model information.

Discovery bashoneliner

system_profiler

Reports system hardware and software configuration.

Discovery bashzsh