T1204.001 Malicious Link
Sub-technique of T1204 User Execution
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Symlink Etc Passwdhightest · linux
- Potential ClickFix Execution Pattern - Registryhighexperimental · windows
- Suspicious ClickFix/FileFix Execution Patternhighexperimental · windows
- Suspicious Execution via macOS Script Editormediumtest · macos
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.