kevmap

TechniquesT1056.002 › AN1442

AN1442 Analytic 1442

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes.</p>
Detects
T1056.002 GUI Input Capture
Part of
DET0521 Behavioral Detection of Spoofed GUI Credential Prompts

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogsubsystem=com.apple.Security or com.apple.applescriptDC0029 Script Execution
macos:osqueryprocess_eventsDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ScriptContentAppleScript snippets like 'display dialog' or 'with hidden answer'
ProcessPathTune out Apple-signed and expected automation tasks