Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕ technique: T1041 ✕
Download CSV Show ATT&CK heatmapUncommon AppleScript was executed via the command line to contact an external server Low 2 variations
The AppleScript interpreter executed a script designed to contact an external server.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Exfiltration (TA0010)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Exfiltration Over C2 Channel (T1041)Required data: XDR AgentDetector tags: AppleScript Analytics, Abnormal Communication AnalyticsAttacker's goals: Exfiltrate collected data, including sensitive documents and credentials, from the compromised system.Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.Variations
Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file
Medium overridden
The AppleScript interpreter executed a script designed to contact an external server. overridden
Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file
Low overridden
The AppleScript interpreter executed a script designed to contact an external server. overridden