T1204 User Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of [Phishing](https://attack.mitre.org/techniques/T1566). While [User…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Droppers Exploiting CVE-2017-11882criticalstable · windows
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- DarkSide Ransomware Patterncriticaltest · windows
- Exploit for CVE-2017-8759criticaltest · windows
- Potential Maze Ransomware Activitycriticaltest · windows
- PrinterNightmare Mimikatz Driver Namecriticaltest · windows
- Antivirus - Hacktool Signaturehighstable · antivirus
- Potential Snatch Ransomware Activityhighstable · windows
- File With Uncommon Extension Created By An Office Applicationhightest · windows
- Flash Player Update from Suspicious Locationhightest · proxy
- GAC DLL Loaded Via Office Applicationshightest · windows
- HackTool - LittleCorporal Generated Maldoc Injectionhightest · windows
- Kapeka Backdoor Loaded Via Rundll32.EXEhightest · windows
- Suspicious Binary In User Directory Spawned From Office Applicationhightest · windows
- Suspicious Microsoft Office Child Processhightest · windows
- Suspicious Microsoft Office Child Process - MacOShightest · macos
- Suspicious Outlook Child Processhightest · windows
- Suspicious Startup Folder Persistencehightest · windows
- Suspicious WMIC Execution Via Office Processhightest · windows
- Suspicious WmiPrvSE Child Processhightest · windows
- Symlink Etc Passwdhightest · linux
- VBA DLL Loaded Via Office Applicationhightest · windows
- FileFix - Command Evidence in TypedPathshighexperimental · windows
- MMC Executing Files with Reversed Extensions Using RTLO Abusehighexperimental · windows
- Potential ClickFix Execution Pattern - Registryhighexperimental · windows
Mostrando 25 de 49.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.