1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1059.002 AppleScript — Attack Simulation

Adversaries may abuse AppleScript for execution. AppleScript is a macOS scripting language designed to control applications and parts of the OS via inter-application messages called AppleEvents. These AppleEvent messages can be sent independently or easily scripted with AppleScript. These events can locate open windows, send keystrokes, and interact with almost any open application locally or remotely. Scripts can be run from the command-line…

Technique description

Adversaries may abuse AppleScript for execution. AppleScript is a macOS scripting language designed to control applications and parts of the OS via inter-application messages called AppleEvents. These AppleEvent messages can be sent independently or easily scripted with AppleScript. These events can locate open windows, send keystrokes, and interact with almost any open application locally or remotely. Scripts can be run from the command-line…

At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

  • AppleScript

    Procedure 3600d97d-81b9-4171-ab96-e4386506e2c2; elevation not declared required; cleanup not declared. Not executed or individually validated.

Connected ecosystem references

Linked tags

Detection and collection

T1059.002 detection workspace

Attack tools

No reviewed association in this snapshot.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.