{"id":"T1059.002","name":"AppleScript","url":"https://attack.mitre.org/techniques/T1059/002","tactics":["execution"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0414","stix_id":"x-mitre-detection-strategy--af66dc57-77fc-42a7-9e84-7a588c3ab516","name":"Detection of AppleScript-Based Execution on macOS","url":"https://attack.mitre.org/detectionstrategies/DET0414","analytics":[{"id":"AN1164","stix_id":"x-mitre-analytic--a67ac8ec-2748-4fe6-8dd7-bd570af1e104","name":"Analytic 1164","description":"Detects AppleScript execution via 'osascript', NSAppleScript/OSAScript APIs, and abnormal application control events across user sessions. Focuses on causal chains such as osascript spawning child processes, script-induced keystrokes, or API-backed dialog spoofing.","url":"https://attack.mitre.org/detectionstrategies/DET0414#AN1164","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process: spawn, exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ScriptInvocationParent","description":"Identify rare or suspicious parent processes launching AppleScript (e.g., Safari, Mail, msedge)."},{"field":"TimeWindow","description":"Flag AppleScript execution during user-inactive hours, especially for automation frameworks."},{"field":"AppleEventActionType","description":"Filter AppleEvent-based automation involving UI interaction, keystrokes, or remote control."},{"field":"TargetApplicationSet","description":"Scope AppleScript use toward security-sensitive apps (e.g., Terminal, ssh, Keychain Access)."},{"field":"ExecutionPathRegex","description":"Restrict to unusual paths like /tmp/, ~/Library/, or embedded in Automator workflows."}],"live":true,"detection_strategies":["DET0414"],"techniques":["T1059.002"]}],"live":true,"version":"1.0","techniques":["T1059.002"]}],"sigma_rules":[{"id":"1bc2e6c5-0885-472b-bed6-be5ea8eace55","title":"MacOS Scripting Interpreter AppleScript","author":"Alejandro Ortuno, oscd.community","status":"test","level":"medium","date":"2020-10-21","modified":"2026-05-21","description":"Detects execution of AppleScript of the macOS scripting language AppleScript.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1059.002/T1059.002.md","https://redcanary.com/blog/applescript/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.t1059.002"],"path":"rules/macos/process_creation/proc_creation_macos_applescript.yml","techniques":["T1059.002"],"cves":[]},{"id":"69483748-1525-4a6c-95ca-90dc8d431b68","title":"Suspicious Microsoft Office Child Process - MacOS","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-01-31","modified":"2023-02-04","description":"Detects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution","references":["https://redcanary.com/blog/applescript/","https://objective-see.org/blog/blog_0x4B.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.persistence","attack.t1059.002","attack.t1137.002","attack.t1204.002"],"path":"rules/macos/process_creation/proc_creation_macos_office_susp_child_processes.yml","techniques":["T1059.002","T1137.002","T1204.002"],"cves":[]},{"id":"6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4","title":"Suspicious Execution via macOS Script Editor","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":"2022-12-28","description":"Detects when the macOS Script Editor utility spawns an unusual child process.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-7f541fbc4a4a28a92970e8bf53effea5bd934604429112c920affb457f5b2685","https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1566","attack.t1566.002","attack.initial-access","attack.t1059","attack.t1059.002","attack.t1204","attack.t1204.001","attack.execution","attack.persistence","attack.t1553"],"path":"rules/macos/process_creation/proc_creation_macos_susp_execution_macos_script_editor.yml","techniques":["T1566","T1566.002","T1059","T1059.002","T1204","T1204.001","T1553"],"cves":[]},{"id":"7794fa3c-edea-4cff-bec7-267dd4770fd7","title":"Clipboard Access Via OSAScript","author":"Sohan G (D4rkCiph3r)","status":"test","level":"medium","date":"2023-01-31","modified":"2026-05-22","description":"Detects access to clipboard content via osascript, which may be used for data collection but also occurs in legitimate clipboard utilities and automation scripts","references":["https://www.sentinelone.com/blog/how-offensive-actors-use-applescript-for-attacking-macos/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.collection","attack.execution","attack.t1115","attack.t1059.002"],"path":"rules/macos/process_creation/proc_creation_macos_clipboard_access_via_osascript.yml","techniques":["T1115","T1059.002"],"cves":[]},{"id":"a09ee860-31b3-4586-8a68-0ebd74ce0e5f","title":"Axios NPM Compromise Indicators - macOS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the macOS-specific execution chain of the plain-crypto-js malicious npm dependency in Axios NPM Package, including AppleScript execution via osascript, payload download, permission modification, execution, and cleanup.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.002","attack.t1059.004","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_macos_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.002","T1059.004","T1105"],"cves":[]},{"id":"a753a6af-3126-426d-8bd0-26ebbcb92254","title":"Osacompile Execution By Potentially Suspicious Applet/Osascript","author":"Sohan G (D4rkCiph3r), Red Canary (Idea)","status":"test","level":"medium","date":"2023-04-03","modified":null,"description":"Detects potential suspicious applet or osascript executing \"osacompile\".","references":["https://redcanary.com/blog/mac-application-bundles/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.t1059.002"],"path":"rules/macos/process_creation/proc_creation_macos_suspicious_applet_behaviour.yml","techniques":["T1059.002"],"cves":[]},{"id":"b9d9b652-d8ed-4697-89a2-a1186ee680ac","title":"OSACompile Run-Only Execution","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-01-31","modified":null,"description":"Detects potential suspicious run-only executions compiled using OSACompile","references":["https://redcanary.com/blog/applescript/","https://ss64.com/osx/osacompile.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.t1059.002","attack.execution"],"path":"rules/macos/process_creation/proc_creation_macos_osacompile_runonly_execution.yml","techniques":["T1059.002"],"cves":[]},{"id":"e710a880-1f18-4417-b6a0-b5afdf7e33da","title":"Atomic MacOS Stealer - FileGrabber Activity","author":"Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital)","status":"experimental","level":"high","date":"2025-11-22","modified":null,"description":"Detects suspicious activity associated with Atomic MacOS Stealer (Amos) campaigns, including execution of FileGrabber and curl-based POST requests used for data exfiltration. The rule identifies either the execution of FileGrabber targeting /tmp or the use of curl to POST sensitive user data (including files such as /tmp/out.zip) to remote servers, which are key indicators of Amos infostealer activity.\n","references":["https://www.trendmicro.com/en_us/research/25/i/an-mdr-analysis-of-the-amos-stealer-campaign.html","https://hunt.io/blog/macos-clickfix-applescript-terminal-phishing","https://github.com/bobby-tablez/TTP-Threat-Feeds/blob/45398914e631f8372c3a9fbcd339ff65ffff1b17/results/2025/10/20251001-161956-trendmicro-atomic-macos-stealer-(amos).yml#L36","https://www.jamf.com/blog/infostealers-pose-threat-to-macos/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.t1059.002","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Atomic-MacOS-Stealer/proc_creation_macos_malware_amos_curl_post.yml","techniques":["T1059.002"],"cves":[]},{"id":"f1408a58-0e94-4165-b80a-da9f96cf6fc3","title":"JXA In-memory Execution Via OSAScript","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-01-31","modified":null,"description":"Detects possible malicious execution of JXA in-memory via OSAScript","references":["https://redcanary.com/blog/applescript/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.t1059.002","attack.t1059.007","attack.execution"],"path":"rules/macos/process_creation/proc_creation_macos_jxa_in_memory_execution.yml","techniques":["T1059.002","T1059.007"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}