{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/e-dr/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["discovery","macos","linux","e-dr","reconnaissance"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003ePost-compromise activity frequently involves situational awareness, where attackers attempt to identify the security posture of an infected host. On macOS and Linux environments, this is often achieved by searching process lists or security software configuration files for indicators of known antivirus, EDR, or firewall solutions. The use of native utilities like \u003ccode\u003egrep\u003c/code\u003e, \u003ccode\u003eegrep\u003c/code\u003e, and \u003ccode\u003epgrep\u003c/code\u003e to filter for common security tool names (e.g., ESET, Sophos, SentinelOne, McAfee) allows an attacker to tailor their next steps, such as disabling agents, using bypasses, or choosing to abandon the host entirely.\u003c/p\u003e\n\u003cp\u003eDefenders must differentiate between legitimate administrative maintenance, patch verification, and malicious reconnaissance. Because security software discovery is a common precursor to more damaging actions, this behavior should trigger investigations into the parent process tree, account behavior, and recent system changes.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains initial access to a macOS or Linux host via an exploit or stolen credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes a foothold and performs internal reconnaissance.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the OS and common installation paths for security software.\u003c/li\u003e\n\u003cli\u003eThe attacker executes \u003ccode\u003egrep\u003c/code\u003e, \u003ccode\u003eegrep\u003c/code\u003e, or \u003ccode\u003epgrep\u003c/code\u003e to query logs, configuration files, or the process list for signatures of security tools (e.g., \u0026quot;Little Snitch\u0026quot;, \u0026quot;kav\u0026quot;, \u0026quot;sophos\u0026quot;, \u0026quot;falcond\u0026quot;).\u003c/li\u003e\n\u003cli\u003eThe utility returns matches confirming the presence and potentially the version of security software.\u003c/li\u003e\n\u003cli\u003eBased on the output, the attacker proceeds to disable or circumvent the identified security controls.\u003c/li\u003e\n\u003cli\u003eThe attacker moves to the final objective, such as data exfiltration or deploying ransomware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful security software discovery provides attackers with the necessary intelligence to evade detection, disable protective measures, and persist within the network. This activity significantly increases the probability of successful data theft or system destruction by allowing attackers to tailor their payloads to the specific defensive environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided detection rules to monitor for \u003ccode\u003egrep\u003c/code\u003e and \u003ccode\u003epgrep\u003c/code\u003e commands targeting security software keywords.\u003c/li\u003e\n\u003cli\u003eInvestigate the parent process tree when these utilities are executed by non-root users, as this is a high-confidence indicator of reconnaissance.\u003c/li\u003e\n\u003cli\u003eBaseline administrative scripts and maintenance tasks to tune out false positives originating from known paths like \u003ccode\u003e/opt/McAfee/\u003c/code\u003e or management frameworks.\u003c/li\u003e\n\u003cli\u003eIsolate systems showing evidence of successful security software discovery to prevent further movement.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:13:51Z","date_published":"2026-09-18T19:13:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-security-software-discovery-via-grep/","summary":"Attackers utilize standard command-line tools like grep and pgrep to enumerate installed security software on macOS and Linux, enabling situational awareness for post-compromise activity.","title":"Detection of Security Software Discovery via Grep on macOS and Linux","url":"https://feed.craftedsignal.io/briefs/2026-09-security-software-discovery-via-grep/"}],"language":"en","title":"CraftedSignal Threat Feed - E-Dr","version":"https://jsonfeed.org/version/1.1"}