Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0002 ✕

Download CSV Show ATT&CK heatmap
  • Uncommon AppleScript containing a potential persistence command was executed via the command line Low 2 variations

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Generic Persistence Analytics
    Attacker's goals: Establish persistence on the system through various mechanisms to maintain access.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting a .plist file for modification

    High overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting launchctl load command execution

    Low overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden