LoFP LoFP / application installers might contain scripts as part of the installation process.

Techniques

Sample rules

MacOS Scripting Interpreter AppleScript

Description

Detects execution of AppleScript of the macOS scripting language AppleScript.

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - ' -e '
  - .scpt
  - .js
  Image|endswith: /osascript