Detection rules › Elastic
Slack Workspace Files Accessed by Osascript
Identifies the Osascript process accessing sensitive Slack files. Adversaries can steal certain Slack files that allows them to log in to the Slack workspace as that user without a password in order to collect additional sensitive data or spy on the organization.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Credential Access |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| macOS | ESF event open (NOTIFY): Fires after the kernel grants a process access to open a file. |
Rule body
[rule]
description = """
Identifies the Osascript process accessing sensitive Slack files. Adversaries can steal certain Slack files that allows
them to log in to the Slack workspace as that user without a password in order to collect additional sensitive data or
spy on the organization.
"""
id = "0e99bc1e-caeb-4a6e-b5ca-5d0d1ee6916c"
license = "Elastic License v2"
name = "Slack Workspace Files Accessed by Osascript"
os_list = ["macos"]
version = "1.0.5"
query = '''
file where event.action == "open" and
file.path like~ ("/Users/*/Library/Application Support/Slack/storage/slack-workspaces.db",
"/Users/*/Library/Application Support/Slack/Cookies.sqlite",
"/Users/*/Library/Containers/com.tinyspeck.slackmacgap/Data/Library/Application Support/Slack/slack-workspaces.db",
"/Users/*/Library/Containers/com.tinyspeck.slackmacgap/Data/Library/Application Support/Slack/Cookies.sqlite") and
process.name == "osascript"
'''
min_endpoint_version = "8.11.1"
optional_actions = []
[[actions]]
action = "kill_process"
field = "Effective_process.executable"
state = 0
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1552"
name = "Unsecured Credentials"
reference = "https://attack.mitre.org/techniques/T1552/"
[[threat.technique.subtechnique]]
id = "T1552.008"
name = "Chat Messages"
reference = "https://attack.mitre.org/techniques/T1552/008/"
[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"
[internal]
min_endpoint_version = "8.11.1"
Stages and Predicates
Stage 1: file
file where event.action == "open" and
file.path like~ ("/Users/*/Library/Application Support/Slack/storage/slack-workspaces.db",
"/Users/*/Library/Application Support/Slack/Cookies.sqlite",
"/Users/*/Library/Containers/com.tinyspeck.slackmacgap/Data/Library/Application Support/Slack/slack-workspaces.db",
"/Users/*/Library/Containers/com.tinyspeck.slackmacgap/Data/Library/Application Support/Slack/Cookies.sqlite") and
process.name == "osascript"
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
event.action | eq |
| field:"EventType" kind:eq value:"open" |
file.path | wildcard |
| field:"TargetFilename" kind:wildcard |
process.name | eq |
| field:"process_name" kind:eq value:"osascript" |