Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕ technique: T1027 ✕
Download CSV Show ATT&CK heatmapUncommon AppleScript containing a potential obfuscation technique was executed Low 2 variations
The AppleScript interpreter process was executed with an obfuscation technique in the command line.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Defense Evasion (TA0005)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Obfuscated Files or Information: Command Obfuscation (T1027.010)Required data: XDR AgentDetector tags: AppleScript Analytics, Evasion AnalyticsAttacker's goals: Evade defenses and impede forensics by encrypting, encoding, or obfuscating payloads at rest or in transit.Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.Variations
Uncommon AppleScript containing a potential obfuscation technique was executed subsequently running a shell command
Medium overridden
The AppleScript interpreter process was executed with an obfuscation technique in the command line. overridden
Uncommon AppleScript containing a potential obfuscation technique was executed by an uncommon parent process
High overridden
The AppleScript interpreter process was executed with an obfuscation technique in the command line. overridden