heroui logo

MacOS Osascript Displaying Suspicious User Prompt

Splunk Security Content

View Source
Summary
This anomaly detects macOS osascript usage that runs AppleScript commands to display a dialog or alert containing content that could be deceptive or related to credentials. Adversaries may use osascript to present fake system messages or credential prompts to trick users into divulging sensitive information. The rule focuses on command-line content from osascript and should be reviewed with the parent process, executing user, script content, signer, and surrounding endpoint activity. It maps to MITRE techniques for scripting (AppleScript) and input/credential-related prompts, and it relies on osquery data populated via the TA-OSquery deployment. Legitimate administrative, MDM, or automation scripts may also display dialogs; review context before flagging as malicious.
Categories
  • Endpoint
  • macOS
Data Sources
  • User Account
  • Process
  • Script
  • Module
  • Application Log
  • Pod
  • Container
  • Windows Registry
  • WMI
  • Kernel
  • Driver
  • File
  • Drive
  • Snapshot
  • Command
  • Sensor Health
  • Volume
  • Network Traffic
  • Scheduled Job
  • Firmware
  • Active Directory
  • Service
  • Domain Name
  • Process
  • Firewall
  • Network Share
  • Malware Repository
  • Cloud Service
  • Cloud Storage
  • Internet Scan
  • Persona
  • Group
  • Logon Session
  • Instance
  • Snapshot
  • Kernel
  • Driver
ATT&CK Techniques
  • T1056
  • T1059
  • T1059.002
  • T1056.002
Created: 2026-09-07