macOS Red Team Tradecraft

macOS Red Team Tradecraft, mapped to the offensive lifecycle

The course is built for authorized macOS operators who need more than disconnected tricks. Each phase follows real red-team workflow, maps to ATT&CK tactics and techniques, and teaches the macOS internals needed to understand why the behavior works, where it fails, and what evidence it creates.

14Phases
109Modules
185TTPs mapped
00

Operator Foundations for the AI-Native Mac

7 modules
0.0Welcome to the AI-Native Mac: Your Path Through This CourseLockedMultiplesupporting methodology
0.1Engagement Workflow, Lab Boundaries, Evidence Handling, and Cleanup on Golden GateLockedMultiplesupporting methodology
0.2The macOS 27 Trust Map: SIP, Code Signing, Gatekeeper, TCC, and the AI Trust PlaneFree previewMultiplesupporting foundation for T1553, T1548.006, T1685, T1686, T1078
0.3Process Identity, Daemon Accounts, and Session Authority on Golden GateLockedDiscovery, Privilege EscalationT1033, T1087.001, T1069.001, T1057
0.4File Artifacts That Affect Delivery, Execution, and OPSEC on Golden GateLockedStealth, Defense Impairment, ExecutionT1553.001, T1564.009, T1564.014, T1204
0.5App Bundles, ExtensionKit, and Mach-O Triage Before Operator ActionLockedExecution, Stealth, Defense ImpairmentT1129, T1553.002, T1036.001, T1204.005
0.6Baseline Telemetry: What macOS 27 Records Before the Operation StartsLockedDiscovery, Stealth, Defense ImpairmentT1070, T1685, T1685.006, T1686, T1654
01

Initial Access and Payload Delivery Tradecraft

9 modules
1.1Designing an Authorized macOS Initial Access Chain on Golden GateLockedInitial AccessT1204, T1566.001, T1189
1.2Payload Delivery Formats: From Script to Installer on Golden GateLockedInitial Access, ExecutionT1204.001, T1204.002, T1204.004, T1204.005, T1546.016
1.3Gatekeeper, Quarantine, Notarization, and User Decisions on Golden GateLockedInitial Access, Defense ImpairmentT1553.001, T1553.002, T1204.002
1.4Installer-Based Execution: PKG Internals, Scripts, and Receipts on Golden GateFree previewExecution, Persistence, Privilege EscalationT1546.016, T1059.004, T1548.004
1.5User-Mediated Execution: URL Schemes, Document Handlers, and Shortcuts on Golden GateLockedInitial Access, ExecutionT1204.001, T1204.002, T1559, T1106
1.6Poisoning the Well: Supply Chain Initial Access on the macOS 27 ToolchainLockedInitial Access, ExecutionT1195.001, T1195.002, T1204
1.7Targeting Common macOS Entry Points on Golden GateLockedInitial Access, ExecutionT1189, T1659, T1218.015, T1176.001
1.8Initial Access Chain Validation: Proof, Weak Assumptions, and ReportingLockedInitial Access, ReportingT1204, T1553.001, T1546.016, T1176.001, T1195.001
1.9Assistant-Mediated Delivery: Content the Intelligence Surface Reads and Acts OnLockedInitial Access, ExecutionT1566.001 shaped content, T1204 user-mediated execution, LLM prompt-injection driving a FoundationModels tool-call
02

Post-Access Command and User-Session Execution

11 modules
2.1Reliable Shell Execution After Access on Golden GateLockedExecutionT1059.004, T1027.010
2.2Living off macOS: Native Utilities, Admin Tools, and Noisy Mistakes on Golden GateLockedExecution, DiscoveryT1059.004, T1106, T1218
2.3AppleEvents and GUI Automation for User-Session OperationsLockedExecutionT1059.002, T1106
2.4JXA Tradecraft and Native Automation Bridges on Golden GateLockedExecutionT1059.007, T1106
2.5Interpreter-Based Execution When the Target Environment Is UncertainLockedExecutionT1059.006, T1059.011
2.6Surviving Rosetta 2: Cross-Architecture Execution, Translation Blind Spots, and ARM64-Aware PayloadsLockedExecution, StealthT1059, T1106, T1027
2.7Native Swift and Objective-C Execution Without Shell ArtifactsLockedExecutionT1106, T1059, T1569
2.8Accessibility, Input Injection, and Session-Bound Execution ClassesLockedExecution, Privilege Escalation, Defense EvasionT1059.007, T1543.011
2.9Choosing an Execution Path Under Defensive MonitoringLockedExecution, Stealth, DetectionT1059.002, T1059.004, T1059.007
2.10Scheduled and Deferred Execution: cron, at, and launchd on Golden GateLockedExecution, PersistenceT1053.003 (cron), T1053.004 (launchd), T1053
2.11Fileless IPC and Staging: Named Pipes, Process Substitution, and File DescriptorsLockedExecution, Defense EvasionT1059.004, T1564 (fileless staging), T1059
03

Loader, Runtime, IPC, and Process Abuse Tradecraft

13 modules
3.1Shaping Process Launch: Parentage, Environment, NSTask, and posix_spawnLockedExecution, StealthT1106, T1036.009, T1059.004
3.2Abusing and Testing dyld Controls in Restricted ContextsLockedExecution, StealthT1574.006, T1129
3.3Run-Path Hijack Surface: @rpath, @loader_path, and @executable_pathLockedExecution, StealthT1574.006, T1129
3.4Dylib Hijacking: Target Discovery, Constructor Execution, and ProofLockedExecution, StealthT1574.004, T1574.006
3.5Dylib Proxying for Stable Execution Inside a Target AppLockedExecution, StealthT1574.004, T1129
3.6DYLD Interposition and API Hooking in Owned ProcessesLockedExecution, Credential AccessT1056.004, T1574.006
3.7XPC and Mach Service Recon for Privilege Boundary MappingLockedExecution, DiscoveryT1559.003, T1007
3.8Exploiting Lab XPC Trust Failures: Audit Tokens, Entitlements, and Client IdentityLockedPrivilege Escalation, ExecutionT1559.003, T1068
3.9Apple Silicon Offensive Tradecraft: 16KB Pages, W^X, PAC, and ARM64 Execution ConstraintsLockedExecution, StealthT1055, T1620, T1027, T1106
3.10Mach Port Rights as Capabilities for IPC and Process ControlLockedExecution, Privilege EscalationT1559, T1055
3.11Process Injection Constraints: task_for_pid, Hardened Runtime, SIP, and AMFILockedStealth, Privilege EscalationT1055, T1620
3.12Runtime Manipulation of Objective-C and Swift AppsLockedStealth, ExecutionT1565.003, T1055, T1027.004
3.13Runtime Tradecraft Review: Loader Abuse, IPC Abuse, Apple Silicon, and Detection PressureLockedExecution, Stealth, DetectionT1574.004, T1574.006, T1055, T1559.003, T1620
04

Post-Compromise Discovery and Target Triage

8 modules
4.1Host Profiling to Choose the Next Operator MoveLockedDiscoveryT1082, T1614, T1497.001
4.2User, Group, Session, and Privilege Enumeration After AccessLockedDiscoveryT1033, T1087.001, T1069.001
4.3Enterprise Footprints: MDM, SSO, Domain, VPN, and Management CluesLockedDiscoveryT1087.002, T1069.002, T1016, T1078
4.4Process, launchd, Login Item, and Background Execution ReconLockedDiscoveryT1057, T1007, T1518, T1518.001
4.5High-Value Application, Browser, Developer, Backup, and Local Data ReconLockedDiscovery, CollectionT1083, T1217, T1654, T1518.002
4.6Network Positioning: Wi-Fi, DNS, Proxy, VPN, Services, and Neighbor HostsLockedDiscoveryT1016, T1016.001, T1016.002, T1049, T1046, T1135
4.7Security Product Discovery: Identifying EDR, Santa, osquery, and Defensive Tooling Without Burning the OperationLockedDiscovery, StealthT1518.001, T1497, T1622
4.8Discovery OPSEC: What to Query, What to Skip, and How to Justify ItLockedDiscovery, ReportingT1057, T1082, T1016, T1518.001
05

Credential Access and Identity Abuse on macOS

6 modules
5.1Keychain Access Tradecraft: ACLs, Prompts, securityd, and Operator LimitsLockedCredential AccessT1555.001
5.2Browser Credential and Session Material Collection with Synthetic DataLockedCredential Access, CollectionT1555.003, T1539, T1606.001
5.3Developer Workstation Secret Hunting: Dotfiles, SSH Keys, Tokens, CLIs, and HistoryLockedCredential Access, DiscoveryT1552.001, T1552.003, T1552.004
5.4Enterprise Identity Material: Kerberos, Platform SSO, Enterprise SSO, and ccacheLockedCredential Access, Lateral MovementT1558.005, T1078
5.5Prompt Abuse Concepts: MFA Requests, Consent Boundaries, and User-Session RiskLockedCredential AccessT1056.002, T1111, T1621
5.6Credential Access Chain Review: Scope Control, Evidence, and Detection PressureLockedCredential Access, DetectionT1555.001, T1555.003, T1552.004, T1056.002
06

Privilege Escalation and macOS Boundary Abuse

7 modules
6.1Elevation Through sudo, askpass, Authorization Prompts, and Cached WindowsLockedPrivilege EscalationT1548.003, T1548.004
6.2Abusing Unsafe Ownership, ACLs, Writable Paths, setuid, and setgidLockedPrivilege Escalation, Defense ImpairmentT1548.001, T1222.002
6.3Privileged Helper Abuse: SMJobBless, Authorization Services, and Helper TrustLockedPrivilege Escalation, PersistenceT1068, T1543.004
6.4LaunchDaemon Root Execution and Privileged Service Install PathsLockedPersistence, Privilege EscalationT1543.004
6.5TCC as an Escalation Boundary: Privacy Grants, Proxying, and Historical AbuseLockedPrivilege Escalation, Defense ImpairmentT1548.006
6.6Privilege Escalation Bug Classes: XPC Auth, Race, Symlink, Helper, and IOKitLockedPrivilege EscalationT1068
6.7Elevation Chain Review: Proof of Impact, Guardrails, Telemetry, and ReportingLockedPrivilege Escalation, DetectionT1548, T1068, T1543.004
07

Persistence and Durable Access Tradecraft

12 modules
7.1LaunchAgent and LaunchDaemon Persistence with Execution ProofLockedPersistence, Privilege EscalationT1543.001, T1543.004
7.2Scheduled and Event-Triggered Persistence with launchd, cron, and atLockedPersistence, ExecutionT1053.002, T1053.003
7.3Login Item and Background Task Management PersistenceLockedPersistenceT1547.015, T1547.007
7.4Shell, Trap, Interpreter, and Developer Workflow PersistenceLockedPersistence, Privilege EscalationT1546.004, T1546.005, T1546.018
7.5Shared Library and Mach-O Load Command PersistenceLockedPersistence, ExecutionT1546.006, T1129
7.6Legacy and Low-Frequency Persistence for Mature EnvironmentsLockedPersistence, Privilege EscalationT1546.014, T1037.002, T1037.004, T1037.005
7.7Host-Application Persistence Through Browser, IDE, and Office-Like ExtensionsLockedPersistence, CollectionT1176.001, T1176.002
7.8Package Script and Installer Receipt Re-Entry PathsLockedPersistence, Privilege EscalationT1546.016
7.9Account-Backed Persistence with SSH Keys, Remote Login, Users, and GroupsLockedPersistence, Privilege EscalationT1098.004, T1098.007, T1136.001
7.10Managed Persistence: Configuration Profiles, Login Items, PPPC, and MDM PolicyLockedPersistence, Defense ImpairmentT1098, T1547.015
7.11Network-Triggered Persistence: Port Knocking, Socket Filters, and Local SignalsLockedPersistence, Command and ControlT1205.001, T1205.002
7.12Persistence Chain Review: Validation, Forensics, Cleanup, and Client EvidenceLockedPersistence, StealthT1070.009, T1543, T1546, T1547
08

OPSEC, Masquerading, and Artifact Discipline

6 modules
8.1Masquerading Tradecraft: Names, Paths, Bundle IDs, Labels, Icons, and TrustLockedStealthT1036.003, T1036.004, T1036.005, T1036.008
8.2Hiding and Blending Artifacts: Finder Flags, xattrs, Resource Forks, and DotfilesLockedStealthT1564.001, T1564.003, T1564.009, T1564.014
8.3Cleanup and Anti-Forensics Tradeoffs: History, Deletion, Timestamps, Receipts, and CachesLockedStealthT1070.003, T1070.004, T1070.006
8.4Payload Appearance Management: Strings, Symbols, Encoding, and Static TriageLockedStealthT1027, T1027.008, T1027.010, T1027.013, T1027.015
8.5Guardrails and Environmental Keying for Lab PayloadsLockedStealth, DiscoveryT1480, T1480.001, T1480.002, T1497, T1622
8.6OPSEC Review: What Reduced Signal, What Became More Suspicious, and WhyLockedStealth, DetectionT1036, T1070, T1564, T1027
09

Defense Evasion Pressure and Trust Control Abuse Classes

7 modules
9.1Gatekeeper, Quarantine, Notarization, and Trust Control Abuse ClassesLockedDefense ImpairmentT1553.001, T1553.002
9.2Code Signing Abuse Classes: Identity, Ad Hoc Signing, Invalid Signatures, and Policy GapsLockedDefense Impairment, StealthT1553.002, T1553.006, T1036.001
9.3Trust Store Abuse Classes: Root Certificates, TLS Inspection, and Proxy VisibilityLockedDefense Impairment, Credential AccessT1553.004
9.4Host Control Tampering: Firewall, Network Filters, DNS, Proxy, and PlistsLockedDefense ImpairmentT1686, T1647
9.5Beating macOS EDR: Endpoint Security Framework Internals, Event Blind Spots, and Evasion MethodologyLockedDefense Impairment, StealthT1685, T1562.001, T1562.006, T1027
9.6Log Tampering, Tool Modification, Sensor Blind Spots, and Defensive TripwiresLockedDefense Impairment, StealthT1685.003, T1685.006
9.7Defense Evasion Review: What Breaks, What Alerts, and What Must Be ReportedLockedDefense Impairment, DetectionT1553, T1685, T1686, T1647
10

Collection and Staging Tradecraft

6 modules
10.1Targeted File and App Data Collection from macOS State StoresLockedCollectionT1005, T1213.006
10.2TCC-Gated Collection: Browser, Mail, Clipboard, Screenshot, Audio, and CameraLockedCollection, Credential AccessT1113, T1114, T1115, T1123, T1125, T1555.003
10.3Collection from Shares, Removable Media, Cloud-Sync, and Collaboration StoresLockedCollectionT1039, T1025, T1213
10.4Staging Tradecraft: Compression, Encryption Concepts, Hashing, Naming, and LimitsLockedCollectionT1074.001, T1074.002, T1560.001, T1560.002, T1560.003
10.5Apple AI Attack Surface: CoreML, Vision, AVFoundation, and Model ArtifactsLockedCollection, Stealth, ExecutionT1005, T1027.009, T1204, T1106
10.6Collection Chain Review: Overcollection Risk, AI Surfaces, Telemetry, and Evidence HandlingLockedCollection, DetectionT1005, T1113, T1115, T1560, T1027.009
11

Command and Control and Operator Channel Design

4 modules
11.1CoreML Operator Channel Design: Tasking, State, Results, Safety, and Kill SwitchesLockedCommand and ControlT1105, T1102, T1071.001
11.2Operator Channel Traffic Shaping: Jitter, Sleep, Encoding, and Detection PressureLockedCommand and Control, StealthT1001.003, T1132, T1008
11.3Operator Channels Under Enterprise Constraints: Proxy, Ports, Tooling, and DetectionLockedCommand and ControlT1090.002, T1105
11.4Operator Channel Review: Beacon Evidence, Endpoint Correlation, and Network Detection LogicLockedCommand and Control, DetectionT1071, T1090, T1105, T1132
12

Lateral Movement and Remote macOS Operations

8 modules
12.1Moving with Valid Accounts: Remote Access Scope, Auth Paths, and EvidenceLockedLateral Movement, Initial Access, PersistenceT1078, T1021
12.2SSH Remote Operations: Authorized Access, Session Artifacts, and HygieneLockedLateral Movement, PersistenceT1021.004, T1098.004, T1563.001
12.3GUI Remote Access: Screen Sharing, Remote Management, and Session BoundariesLockedLateral Movement, CollectionT1021.005, T1219.002
12.4Remote Apple Events and Apple-Native Service MovementLockedLateral Movement, ExecutionT1021, T1059.002, T1078
12.5SMB File Sharing and Share-Based MovementLockedLateral Movement, CollectionT1021.002, T1080, T1078
12.6Lateral Tool Transfer: Synthetic Artifacts, Quarantine Propagation, and Execution ProofLockedLateral Movement, ExecutionT1570, T1080
12.7Admin and Deployment-System Trust Boundaries for macOS FleetsLockedLateral Movement, ExecutionT1072
12.8Lateral Movement Chain Review: Source, Destination, and Network EvidenceLockedLateral Movement, DetectionT1021.004, T1021.005, T1570, T1072
13

Impact Simulation and Business-Risk Demonstration

5 modules
13.1Simulated Data Destruction and File Encryption Against Disposable DataLockedImpactT1485, T1486
13.2Service Interruption, Recovery Inhibition Concepts, and launchd Job ControlLockedImpactT1489, T1490, T1529
13.3Stored Data Manipulation and Defacement in the Training AppLockedImpactT1491.001, T1565.001, T1565.003
13.4Resource Abuse, Bandwidth Pressure, and Safe Availability TestingLockedImpactT1496, T1496.001, T1496.002
13.5Impact Simulation Review: Recovery Evidence, Business Framing, and Safety BoundariesLockedImpact, DetectionT1485, T1486, T1489, T1565