Rare process executed by an AppleScript
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
AppleScript Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: AppleScript (T1059.002)
Severity
Low
Description
An uncommon process has been executed by the AppleScript interpreter process.
Attacker's Goals
Use the AppleScript interpreter to execute a second-stage payload.
Investigative actions
Analyze the AppleScript and executed process to determine whether they perform any malicious or suspicious actions.
Check the events generated by the process or its children for potential malicious behavior.
Check whether the AppleScript was executed in an unusual way.
PreviousRare process created an SSH session to an uncommon external host
NextRare process execution by user
Was this helpful?
