SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

Create new rule: proc_creation_macos_tmutil_backup_tampering.yml #4865

Closed pratinavchandra closed 4 weeks ago

pratinavchandra commented 1 month ago

Summary of the Pull Request

Added a new rule to detect tampering with Time Machine, Apple's automated backup utility software. Attackers can use this to prevent backups from occurring and hinder the victim's ability to recover from any damage.

image image

Changelog

new: Time Machine Backup Deletion Attempt Via Tmutil - MacOS new: Time Machine Backup Disabled Via Tmutil - MacOS new: New File Exclusion Added To Time Machine Via Tmutil - MacOS

Example Log Event

image

Fixed Issues

SigmaHQ Rule Creation Conventions