INTEL_REPORT
Palo Alto Networks Unit 42 · published 6/12/2026, 10:00:14 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42 . Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Insights General General Tra…
https://unit42.paloaltonetworks.com/new-macos-artifact-discovered
sha256:85e4c5c57b904a8909307874a22355076c0f89dadfe3c2d06e4bdf2898a8fe2d
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |