T1059.002: AppleScript
Adversaries may abuse AppleScript commands or osascript to execute malicious code, harvest credentials via fake prompts, or interact with macOS services.
Total Capable Binaries: 1
•
Windows: 0
•
Linux: 0
•
macOS: 1
Living-off-the-Land Matrix for T1059.002
Across 1 verified binariesmacOS2 payloads
osascript
Osascript executes Open Scripting Architecture (OSA) scripts such as AppleScript and JavaScript for Automation (JXA). Widely used in macOS malware to display convincing phishing dialogs, harvest credentials, control System Events, and execute shell commands.
Sample Attack Vector:
osascript -e 'display dialog "System Update requires your password to continue:" default answer "" with hidden answer with icon caution'Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point