Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0009 ✕ technique: T1213 ✕
Download CSV Show ATT&CK heatmapUnusual process accessed a macOS notes DB file Informational 1 variation
An unusual process has accessed a user's notes DB file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Information Repositories (T1213)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Sensitive Information Stealing AnalyticsAttacker's goals: Obtain access to user's notes and steal their contents.Investigative actions: Determine whether it is legitimate for the process to access user's notes. Analyze the process/application that accessed the DB file. Check for any other suspicious actions that were performed by the process. Look for unusual access of resources using credentials that may be stored in the above notes.Variations
Unusual unsigned process accessed a macOS notes DB file
Low overridden
An unusual process has accessed a user's notes DB file. overridden