The DisguisedExecutable analytic will detect execution of Mach-O binaries with a contradictory file extension.
The macOS interface is regarded as being very user-focused. It has helpful and recognizable visual icons that correspond to a wide array of different file types. Unfortunately, the visual icons are based solely on the extension in the file name. Threat actors often disguise malware by using a file extension that is familiar to users, causing macOS to display the icon of the executable as that of a common file format such as a Preview document (.pdf) or Microsoft Word (.docx). This raises less suspicion than the standard executable icon and increases the likelihood of the user ignoring it.
For more information about this type of threat see MITRE ATT&CK Tactic: Defense Evasion and MITRE ATT&CK Technique: Masquerading: Match Legitimate Name or Location.