For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

AppleScript Analytics, Sensitive Information Stealing Analytics

ATT&CK Tactic

Execution (TA0002), Collection (TA0009)

ATT&CK Technique

Command and Scripting Interpreter: AppleScript (T1059.002), Screen Capture (T1113), Clipboard Data (T1115)

Severity

Low

Description

The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.

Attacker's Goals

Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.

Investigative actions

  • Determine whether the screen capture or clipboard access was initiated by a legitimate application.

  • Check if the captured data was written to a suspicious location or exfiltrated.

  • Verify whether the user was aware of the screen capture activity.

Was this helpful?