Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
AppleScript Analytics, Sensitive Information Stealing Analytics
ATT&CK Tactic
Execution (TA0002), Collection (TA0009)
ATT&CK Technique
Command and Scripting Interpreter: AppleScript (T1059.002), Screen Capture (T1113), Clipboard Data (T1115)
Severity
Low
Description
The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.
Attacker's Goals
Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.
Investigative actions
Determine whether the screen capture or clipboard access was initiated by a legitimate application.
Check if the captured data was written to a suspicious location or exfiltrated.
Verify whether the user was aware of the screen capture activity.
Was this helpful?
