Analytics Alerts
Browse the Cortex analytics alert reference.
2 alerts match the current filters. tactic: TA0002 ✕ technique: T1005 ✕
Download CSV Show ATT&CK heatmapUncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line Informational 1 variation
The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.Investigative actions: Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.Variations
Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files
Medium overridden
The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. overridden
Uncommon AppleScript designed to access sensitive application data was executed via the command line High
The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.Investigative actions: Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.