Analytics BIOC Informational

Unusual process accessed a macOS notes DB file

An unusual process has accessed a user's notes DB file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories (T1213)
Detector tags: Sensitive Information Stealing Analytics
Attacker's goals:

Obtain access to user's notes and steal their contents.

Investigative actions:

Determine whether it is legitimate for the process to access user's notes. Analyze the process/application that accessed the DB file. Check for any other suspicious actions that were performed by the process. Look for unusual access of resources using credentials that may be stored in the above notes.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual unsigned process accessed a macOS notes DB file Low (parent: Informational)