Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon AppleScript was executed via the command line to contact an external server Low 2 variations

    The AppleScript interpreter executed a script designed to contact an external server.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Exfiltration (TA0010)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Exfiltration Over C2 Channel (T1041)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Abnormal Communication Analytics
    Attacker's goals: Exfiltrate collected data, including sensitive documents and credentials, from the compromised system.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file

    Medium overridden

    The AppleScript interpreter executed a script designed to contact an external server. overridden

    Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file

    Low overridden

    The AppleScript interpreter executed a script designed to contact an external server. overridden