IH-PRIV-001highPrivilege

Privilege or OS protection bypass

sudo, broad chmod, and commands that turn off Gatekeeper or firewall protections weaken the host.

What does IH-PRIV-001 flag?

Flags sudo, broad or executable chmod, and commands that remove macOS quarantine or turn off Gatekeeper, antivirus or firewall protections.

  • The word sudo.
  • chmod 777, 666, 755, +x, a+x or u+x, with or without -R.
  • xattr -d or -c on the same line as the word quarantine, and spctl --master-disable.
  • disable or turn off near gatekeeper, antivirus, firewall or real-time protection; ufw disable; iptables -F; DisableRealtimeMonitoring.

Why it matters

Elevated privileges and disabled protections widen what a mistake can damage. Reported macOS droppers marked downloads executable and stripped extended attributes so the system would run them without warning.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Elevation
Flagged
sudo bash install.sh
Quarantine removal
Flagged
xattr -d com.apple.quarantine ./tool
Current user
Not flagged
Run the command as the current user.

Can IH-PRIV-001 fire on a safe skill?

  • chmod +x on the skill's own script is common and often harmless.
  • Docs that install system packages with sudo.

How do I fix an IH-PRIV-001 finding?

  • Do not elevate privileges or remove operating-system protections.
  • Ask the user to install software through the normal path.

CLI guidance: Do not elevate privileges or remove OS protections.

How do I tune or allow IH-PRIV-001?

If chmod +x on a bundled script is expected, review the script and lower the severity for that project with ruleOverrides.

{
  "ruleOverrides": {
    "IH-PRIV-001": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-PRIV-001.

What can IH-PRIV-001 miss?

  • Clearing all extended attributes (xattr -c) without the word quarantine on the same line.
  • Privilege prompts faked by a payload after it runs.
  • Elevation through other tools such as doas or pkexec, or PowerShell's run-as.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

In the tracker

Publicly reported cases where a synthetic copy of the reported pattern raises IH-PRIV-001. Coverage is about the pattern, not a scan of the original files.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules