Esc
Gatekeeper Bypass - T1553.001
(ATT&CK® Technique)
Definition
Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper also treats applications running for the first time differently than reopened applications.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.