Digital Forensics and Incident Response | DFIR
  • Blog
  • Infosec
  • Windows Forensics
  • Mac Forensics
  • Memory Forensics
  • Incident Response
  • CISSP

macOs Autoruns?

7/20/2019

1 Comment

 
.Super Cool Investigative information for a Malware type investigations. This is one of the way modern malware maintains persistence in the system across shutdowns and reboots.
  • LaunchAgents
    • User Level and contains background user process
    • /System/Library/LaunchAgents
    • /Library/LaunchAgents
    • ~/Library/LaunchAgents
  • LaunchDaemons 
    • Background System Process for MacOs
    • /System/Library/LaunchDaemons
    • /Library/LaunchDeamons
  • StartupItems
  • LoginItems - ~/Library/Preferencescom.apple.loginitems.plist
1 Comment
Jeralyn Nichole
12/6/2021 02:29:34 pm

I have discovered the fastest money/loan funder in the entire US. He can fund you with as much as 300k just like he did mine I'm quite overwhelmed, can't believe a blank debit card which contains about $75k in it was issued to me by jamiehacking99 @ gmail . com, the amount in the card renews after every 60 days, it's a splendid algorithm hack for ATM's, so you can withdraw limitlessly without being noticed. They also repair credit reports in 2 weeks.

Reply



Leave a Reply.

    Archives

    July 2019
    April 2018

    Categories

    All
    Plist

    RSS Feed