Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line Informational 1 variation

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.
    Investigative actions: Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.

    Variations

    Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files

    Medium overridden

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. overridden

  • Uncommon AppleScript designed to access sensitive application data was executed via the command line High

    The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.
    Investigative actions: Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.
  • Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line Low

    The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Screen Capture (T1113) Clipboard Data (T1115)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.
    Investigative actions: Determine whether the screen capture or clipboard access was initiated by a legitimate application. Check if the captured data was written to a suspicious location or exfiltrated. Verify whether the user was aware of the screen capture activity.