Skip to main content

Summary

This uses AppleEvents or ObjectiveC APIs to get information about the current user.
  • Needs Admin: False
  • Version: 1
  • Author: @its_a_feature_
If the JXA method is selected: In Mojave+ (10.14+) this will cause a popup the first time asking for permission for your process to access System Events.

Arguments

method

  • Description: Use AppleEvents or ObjectiveC calls to get user information
  • Required Value: True
  • Default Value: api

Usage

MITRE ATT&CK Mapping

  • T1033

Detailed Summary

This boils down to AppleEvents to System Events or an ObjectiveC API call: