Skip to content
Persistenceintermediate

Login Item Persistence

Registering an app as a macOS Login Item via SMAppService or the legacy shared-file-list API — a persistence surface separate from LaunchAgents, driven through System Settings rather than a launchd plist.

Login Items are a persistence surface distinct from LaunchAgents/LaunchDaemons: apps registered to open automatically at login through System Settings > General > Login Items, historically configured via the Shared File List API or osascript's System Events Login Items object, and on modern macOS via the SMAppService framework, which registers a helper tool or agent alongside a main app bundle without writing a separate LaunchAgent plist by hand. Because this mechanism is UI-driven rather than a raw property list, it was historically less scrutinized by defenders whose tooling only enumerated ~/Library/LaunchAgents and /Library/LaunchAgents; anything on this surface never showed up there at all.

How it works

The legacy route scripts the Shared File List directly:

applescript
tell application "System Events"
  make login item at end with properties {path:"/Users/victim/Library/Application Support/.helper/agent.app", hidden:true}
end tell

The modern route, used by apps targeting current macOS, registers a SMAppService login item or agent programmatically from within the app's own code — the OS then manages starting it at login and tracks the registration in its Background Task Management (BTM) database rather than a plist an analyst can just cat.

Detection & analysis

Static analysis:

  • A sample that calls into ServiceManagement/SMAppService APIs, or shells out to osascript with a System Events ... login item script, is registering itself for login persistence through this surface specifically — distinguish it from LaunchAgent-based persistence in your notes, since the remediation path differs.
  • Inspect an app bundle's Info.plist for SMAuthorizedClients/ SMPrivilegedExecutables keys that name a helper tool intended to be registered this way.

Dynamic analysis:

  • sfltool dumpbtm enumerates the Background Task Management database on current macOS, listing every registered login item, agent, and daemon regardless of which API registered it — this is the authoritative modern view, since it also catches entries LaunchAgent-only tooling misses.
  • System Settings > General > Login Items & Extensions shows the same list to a human reviewer; compare it against a known-good baseline for the machine.

Detection rule hint:

Alert on new entries appearing in the BTM database (sfltool dumpbtm) or the Shared File List login-items store whose target binary is unsigned, ad-hoc signed, or resides outside /Applications, especially when the registering process is not a package installer.

Votes

Comments(0)