Analytics BIOC Informational

AppleScript process executed with a rare command line

The AppleScript interpreter process was executed with an uncommon command line.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002)
Detector tags: AppleScript Analytics
Attacker's goals:

Perform various actions via AppleScript code, such as establishing persistence, evading detection, executing secondary payloads or injecting remote processes.

Investigative actions:

Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Check whether the process was executed in an unusual way.

Test period:
N/A (single event)
Deduplication:
1 Day
6 variations:
  • AppleScript process executed with a rare command line containing uncommon arguments High (parent: Informational)
  • AppleScript process executed with a rare command line possibly using Finder to perform operations High (parent: Informational)
  • AppleScript process executed with a rare command line with an unusual password prompt Low (parent: Informational)
  • AppleScript process executed with a rare command line that possibly injects JavaScript into a browser Low (parent: Informational)
  • AppleScript process executed with a rare command line performing clipboard access Low (parent: Informational)
  • AppleScript process executed with a rare command line that muted the audio output Low (parent: Informational)