T1059.002Tactic: ExecutionOfficial MITRE ATT&CK Page

T1059.002: AppleScript

Adversaries may abuse AppleScript commands or osascript to execute malicious code, harvest credentials via fake prompts, or interact with macOS services.

Total Capable Binaries: 1
Windows: 0
Linux: 0
macOS: 1

Living-off-the-Land Matrix for T1059.002

Across 1 verified binaries
macOS2 payloads

osascript

Osascript executes Open Scripting Architecture (OSA) scripts such as AppleScript and JavaScript for Automation (JXA). Widely used in macOS malware to display convincing phishing dialogs, harvest credentials, control System Events, and execute shell commands.

Sample Attack Vector:
osascript -e 'display dialog "System Update requires your password to continue:" default answer "" with hidden answer with icon caution'
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point