T1204.002 Malicious File
Subtécnica de T1204 User Execution
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Droppers Exploiting CVE-2017-11882criticalstable · windows
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- Exploit for CVE-2017-8759criticaltest · windows
- Potential Maze Ransomware Activitycriticaltest · windows
- File With Uncommon Extension Created By An Office Applicationhightest · windows
- Flash Player Update from Suspicious Locationhightest · proxy
- GAC DLL Loaded Via Office Applicationshightest · windows
- HackTool - LittleCorporal Generated Maldoc Injectionhightest · windows
- Kapeka Backdoor Loaded Via Rundll32.EXEhightest · windows
- Suspicious Binary In User Directory Spawned From Office Applicationhightest · windows
- Suspicious Microsoft Office Child Processhightest · windows
- Suspicious Microsoft Office Child Process - MacOShightest · macos
- Suspicious Outlook Child Processhightest · windows
- Suspicious Startup Folder Persistencehightest · windows
- Suspicious WMIC Execution Via Office Processhightest · windows
- Suspicious WmiPrvSE Child Processhightest · windows
- VBA DLL Loaded Via Office Applicationhightest · windows
- MMC Executing Files with Reversed Extensions Using RTLO Abusehighexperimental · windows
- Suspicious LNK Command-Line Padding with Whitespace Charactershighexperimental · windows
- TanStack Supply-Chain Attack Execution Indicators - Linuxhighexperimental · linux
- TanStack Supply-Chain Attack Execution Indicators - Windowshighexperimental · windows
- AppLocker Prevented Application or Script from Runningmediumtest · windows
- CLR DLL Loaded Via Office Applicationsmediumtest · windows
- DotNET Assembly DLL Loaded Via Office Applicationmediumtest · windows
- Exploit for CVE-2017-0261mediumtest · windows
Mostrando 25 de 32.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.