Unusual process accessed a macOS notes DB file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Sensitive Information Stealing Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Information Repositories (T1213)
Severity
Informational
Description
An unusual process has accessed a user's notes DB file.
Attacker's Goals
Obtain access to user's notes and steal their contents.
Investigative actions
Determine whether it is legitimate for the process to access user's notes.
Analyze the process/application that accessed the DB file.
Check for any other suspicious actions that were performed by the process.
Look for unusual access of resources using credentials that may be stored in the above notes.
Variations
Was this helpful?
