Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line Low

    The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Screen Capture (T1113) Clipboard Data (T1115)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.
    Investigative actions: Determine whether the screen capture or clipboard access was initiated by a legitimate application. Check if the captured data was written to a suspicious location or exfiltrated. Verify whether the user was aware of the screen capture activity.