Analytics BIOC High

Uncommon AppleScript designed to access sensitive application data was executed via the command line

The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Collection (TA0009)
ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
Detector tags: AppleScript Analytics Sensitive Information Stealing Analytics
Attacker's goals:

Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.

Investigative actions:

Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.

Test period:
N/A (single event)
Deduplication:
1 Day