macOS PAM Hook Abuse with Spoofed Credential Prompt

This rule detects a sequence of events indicative of MacSync credential phishing on macOS. It identifies the tampering of Pluggable Authentication Modules (PAM) configuration files or SecurityAgent plugins (often used to hook authentication processes), immediately followed by the use of osascript to display a spoofed password dialog to the user. This combined activity suggests an adversary is attempting to harvest local user account credentials.