Analytics BIOC
Low
✕
Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords
The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Credentials from Password Stores (T1555)
Detector tags: AppleScript Analytics Credentials Grabbing Analytics
Attacker's goals:
Harvest user credentials and passwords from sensitive locations such as the macOS Keychain or directory services to enable unauthorized access, lateral movement, or privilege escalation.
Investigative actions:
Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Check whether the process was executed in an unusual way.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords leveraging the 'dscl -authonly' command to covertly verify the captured password High (parent: Low) Adds Valid Accounts (T1078)