Title:
Clipboard Access Via OSAScript
Status:
test
Description:Detects access to clipboard content via osascript, which may be used for data collection but also occurs in legitimate clipboard utilities and automation scripts
References:
-https://www.sentinelone.com/blog/how-offensive-actors-use-applescript-for-attacking-macos/
Author: Sohan G (D4rkCiph3r)
Date: 2023-01-31
modified:2026-05-22
Tags:
- -'attack.collection'
- -'attack.execution'
- -'attack.t1115'
- -'attack.t1059.002'
Logsource:
- product: macos
- category: process_creation
Detection:
selection:
Image|endswith:
'/osascript'
CommandLine|contains|all:
-' -e '
-'clipboard'
filter_optional_opencode:
ParentImage|endswith:
'opencode'
CommandLine|contains|all:
-'osascript'
-' -e '
-'set imageData to the clipboard'
-'set fileRef'
condition:
selection and not 1 of filter_optional_*
Falsepositives:
-Legitimate clipboard utilities and automation scripts that read or write clipboard content
-Developer tools and IDEs that use osascript for clipboard integration
Level:
medium