Credential Access
- Category
- Privilege Escalation
- Confidence
- 90% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md - [ ] **1. Remote desktop as a service, not an app.** Whatever tool you use must be a login item *and* allowed in the background (System Settings → General → Login Items & Extensions), with a permanent unattended password and its privacy grants. A remote-desktop app launched by hand dies with the session — the classic way a Mac becomes unreachable at the login window. - [ ] **2. Tailscale, formula build** (§Tailscale). - [ ] **3. Remote Login (sshd)** + your public key in the agent account's `~/.ssh/authorized_keys` (mode 600, dir 700). - [ ] **4. Power** (§Power), verified in the same line. - [ ] **5. The login decision** (§Read first): Option A or B, by a human, in System Settings. - [ ] **6. Agent service** installed as a LaunchAgent of the agent account (see `always-on-agent-ops` for the gateway itself).
