Analytics Alerts
Browse the Cortex analytics alert reference.
3 alerts match the current filters. tactic: TA0009 ✕ technique: T1059 ✕
Download CSV Show ATT&CK heatmapUncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line Informational 1 variation
The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.Investigative actions: Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.Variations
Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files
Medium overridden
The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. overridden
Uncommon AppleScript designed to access sensitive application data was executed via the command line High
The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.Investigative actions: Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line Low
The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Collection (TA0009)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Screen Capture (T1113) Clipboard Data (T1115)Required data: XDR AgentDetector tags: AppleScript Analytics, Sensitive Information Stealing AnalyticsAttacker's goals: Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.Investigative actions: Determine whether the screen capture or clipboard access was initiated by a legitimate application. Check if the captured data was written to a suspicious location or exfiltrated. Verify whether the user was aware of the screen capture activity.