Disk Image Creation Via Hdiutil - MacOS

Rule Info

Name
Disk Image Creation Via Hdiutil - MacOS
Author
Omar Khaled (@beacon_exe)
Description
Detects the execution of the hdiutil utility in order to create a disk image.
Date
2024-08-10 00:00:00
Modified
None
Id
1cf98dc2-fcb0-47c9-8aea-654c9284d1ae
Tags
attack.exfiltration DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Omar A.
Merge PR #4949 from @omaramin17 - Add new rules related to Hdiutil usage
2024-08-10