rule Persistence_Agent_MacOS { meta: description = "Detects a Python agent that establishes persistence on macOS" author = "John Lambert @JohnLaTwC" reference = "https://ghostbin.com/paste/mz5nf" hash = "4288a81779a492b5b02bad6e90b2fa6212fa5f8ee87cc5ec9286ab523fc02446 cec7be2126d388707907b4f9d681121fd1e3ca9f828c029b02340ab1331a5524 e1cf136be50c4486ae8f5e408af80b90229f3027511b4beed69495a042af95be" id = "9c69af3c-ee85-58ac-8b78-66760addc117" strings: $h1 = "#!/usr/bin/env python" $s_1= "