Detection rules › Elastic

Telegram Data Accessed by Osascript

Source
github.com/elastic/protections-artifacts

Identifies the Osascript process accessing Telegram data. Adversaries can steal Telegram files that will allow them access to sensitive data or the ability to login and spy on the user.

MITRE ATT&CK coverage

Telemetry coverage

Rule body

[rule]
description = """
Identifies the Osascript process accessing Telegram data. Adversaries can steal Telegram files that will allow them
access to sensitive data or the ability to login and spy on the user.
"""
id = "b11b4670-7368-4269-b199-8c90ed8db511"
license = "Elastic License v2"
name = "Telegram Data Accessed by Osascript"
os_list = ["macos"]
version = "1.0.5"

query = '''
file where event.action == "open" and 
 file.path like~ "/Users/*/Library/Application Support/Telegram Desktop/tdata/*" and 
 process.name == "osascript"
'''

min_endpoint_version = "8.11.1"
optional_actions = []
[[actions]]
action = "kill_process"
field = "Effective_process.executable"
state = 0

[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1552"
name = "Unsecured Credentials"
reference = "https://attack.mitre.org/techniques/T1552/"
[[threat.technique.subtechnique]]
id = "T1552.001"
name = "Credentials In Files"
reference = "https://attack.mitre.org/techniques/T1552/001/"



[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "8.11.1"

Stages and Predicates

Stage 1: file

file where event.action == "open" and 
 file.path like~ "/Users/*/Library/Application Support/Telegram Desktop/tdata/*" and 
 process.name == "osascript"

Indicators

These rows show field, operator, and value matches.