← All Tags

bash

25 binaries with this tag

caffeinate

Prevent the system from sleeping on behalf of a utility.

ExecutionDefense Evasion bashzsh

disown

Prevents a process from being terminated when a shell session or terminal is closed.

Persistence bash

dscacheutil

gather information, statistics and initiate queries to the Directory Service cache.

Discovery bashzsh

dsconfigad

retrieves/changes configuration for Directory Services Active Directory Plugin.

Discovery bashzsh

funzip

The malicious binaries use funzip to extract the malicious binary with a password and using head or tail commands.

Execution bashzsh

GetFileInfo

Get attributes of files and directories.

Discovery bashzshoneliner

hdiutil

Manipulate disk images using the DiskImages framework.

ExecutionCollection bashzshdisk

ioreg

Displays a hierarchial view of the I/O Kit registry.

DiscoveryCollection bashonelinerlockscreen +1

kextstat

Display the status of loaded kernel extensions (kexts)

Discovery bashzshkernel

launchctl

Interact with LaunchAgents and LaunchDaemons.

ExecutionPersistence bashzshoneliner

log

Access system log messages from Apple Unified Logging (AUL).

Defense EvasionCredential Access requires-rootbashzsh

mdfind

Locate files using the Spotlight database.

ReconnaissanceDiscoveryDefense Evasion bashzshoneliner +2

odutil

odutil allows caller to examine or change state of opendirectoryd

Discovery bashzsh

osascript

Execute AppleScripts and other OSA language scripts and commands.

CollectionCredential AccessDiscovery +4 clipboardbashoneliner +15

pbpaste

Paste the contents of clipboard to the terminal.

Credential AccessCollection bashoneliner

say

Convert text to audible speech.

Defense EvasionCollectionReconnaissance +1 bashpbpasteclipboard +1

security

Interact with Keychain, macOS's built-in password manager.

Credential AccessDefense Evasion bashchromecertificate

SetFile

Set attributes of files and directories.

PersistenceDefense Evasion bashzshoneliner

sfltool

Binary to manage the Shared File List framework.

DiscoveryDefense Evasion bashstartupsystem-reset

sw_vers

Prints macOS version information.

Discovery bashconfiguration

swift

Arbitrarily execute swift code from the terminal.

ExecutionDefense Evasion swiftreplbash +1

sysctl

Get macOS hardware model information.

Discovery bashoneliner

system_profiler

Reports system hardware and software configuration.

Discovery bashzsh

tccutil

Command-line tool for managing the Transparency, Consent, and Control (TCC) permissions database

Defense Evasion bashtccutil

textutil

Manipulate text files in various formats.

Defense EvasionCollectionCredential Access bashonelinerpbpaste +1