Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line Informational 1 variation

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.
    Investigative actions: Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.

    Variations

    Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files

    Medium overridden

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. overridden

  • Uncommon AppleScript designed to access sensitive application data was executed via the command line High

    The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.
    Investigative actions: Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.