Uncommon AppleScript designed to access sensitive application data was executed via the command line
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
AppleScript Analytics, Sensitive Information Stealing Analytics
ATT&CK Tactic
Execution (TA0002), Collection (TA0009)
ATT&CK Technique
Command and Scripting Interpreter: AppleScript (T1059.002), Data from Local System (T1005)
Severity
High
Description
The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.
Attacker's Goals
Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.
Investigative actions
Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.).
Check if application databases or message stores were copied or exfiltrated.
Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity.
Examine child processes for signs of data exfiltration.
Was this helpful?
