Analytics BIOC
Low
✕
Uncommon AppleScript was executed via the command line to contact an external server
The AppleScript interpreter executed a script designed to contact an external server.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Exfiltration (TA0010)
ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Exfiltration Over C2 Channel (T1041)
Detector tags: AppleScript Analytics Abnormal Communication Analytics
Attacker's goals:
Exfiltrate collected data, including sensitive documents and credentials, from the compromised system.
Investigative actions:
Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file Medium (parent: Low)
- Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file Low