You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A user has executed a ioreg command not seen since the baseline period. The ioreg binary can be used to enumerate configurations on a Unix/macOS host and can be used by malware to ensure that code is not running on a virtual machine or sandbox. This rule utilizes data from the "LOOBins" project: https://github.com/infosecB/LOOBins - more information regarding this specific binary can be found via: https://www.loobins.io/binaries/ioreg/
Additional Details
Detail
Value
Type
First Seen
Category
Discovery
Apply Risk to Entities
user_username
Signal Name
First Seen Ioreg Usage from User
Summary Expression
{{user_username}} has executed a ioreg command from {{device_hostname}}