Digital Forensics and Incident Response | DFIR
  • Blog
  • Infosec
  • Windows Forensics
  • Mac Forensics
  • Memory Forensics
  • Incident Response
  • Contact

macOs Autoruns?

7/20/2019

0 Comments

 
.Super Cool Investigative information for a Malware type investigations. This is one of the way modern malware maintains persistence in the system across shutdowns and reboots.
  • LaunchAgents
    • User Level and contains background user process
    • /System/Library/LaunchAgents
    • /Library/LaunchAgents
    • ~/Library/LaunchAgents
  • LaunchDaemons 
    • Background System Process for MacOs
    • /System/Library/LaunchDaemons
    • /Library/LaunchDeamons
  • StartupItems
  • LoginItems - ~/Library/Preferencescom.apple.loginitems.plist
0 Comments



Leave a Reply.

    Archives

    July 2019
    April 2018

    Categories

    All
    Plist

    RSS Feed