User Execution: Malicious File T1204.002
Tactic: Execution
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Events covered
25 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 145 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (93 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (1125 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (280 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 36 rules
- AppLocker Prevented Application or Script from Running
- CLR DLL Loaded Via Office Applications
- DotNET Assembly DLL Loaded Via Office Application
- Download From Suspicious TLD - Blacklist
- Download From Suspicious TLD - Whitelist
- Droppers Exploiting CVE-2017-11882
- Exploit for CVE-2017-0261
- Exploit for CVE-2017-8759
- File With Uncommon Extension Created By An Office Application
- Flash Player Update from Suspicious Location
- GAC DLL Loaded Via Office Applications
- HackTool - LittleCorporal Generated Maldoc Injection
- Kapeka Backdoor Loaded Via Rundll32.EXE
- Microsoft Excel Add-In Loaded
- Microsoft Excel Add-In Loaded From Uncommon Location
- Microsoft VBA For Outlook Addin Loaded Via Outlook
- Microsoft Word Add-In Loaded
- MMC Executing Files with Reversed Extensions Using RTLO Abuse
- New Application in AppCompat
- Potential Maze Ransomware Activity
- Potential Suspicious Browser Launch From Document Reader Process
- Remote DLL Load Via Rundll32.EXE
- Successful MSIX/AppX Package Installation
- Suspicious Binary In User Directory Spawned From Office Application
- Suspicious LNK Command-Line Padding with Whitespace Characters
- Suspicious Microsoft Office Child Process
- Suspicious Microsoft Office Child Process - MacOS
- Suspicious Outlook Child Process
- Suspicious Startup Folder Persistence
- Suspicious WMIC Execution Via Office Process
- Suspicious WmiPrvSE Child Process
- Ursnif Malware C2 URL Pattern
- VBA DLL Loaded Via Office Application
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- Windows MSIX Package Support Framework AI_STUBS Execution
Elastic 49 rules
- Anomalous Process For a Windows Population
- Anomalous Windows Process Creation
- Base64 Decoded Payload Piped to Interpreter
- Creation of SettingContent-ms Files
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Downloaded Shortcut Files
- Downloaded URL Files
- Elastic Defend Alert Followed by Telemetry Loss
- Encoded Payload Detected via Defend for Containers
- Executable File Creation with Multiple Extensions
- Executable File Download via Wget
- Execution of a Downloaded Windows Script
- Execution of File Written or Modified by Microsoft Office
- File with Right-to-Left Override Character (RTLO) Created/Executed
- File with Suspicious Extension Downloaded
- Gatekeeper Override and Execution
- Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
- M365 Threat Intelligence Signal
- Malicious File - Detected - Elastic Defend
- Malicious File - Prevented - Elastic Defend
- Masquerading Space After Filename
- Microsoft Build Engine Started by an Office Application
- Microsoft Management Console File from Unusual Path
- MS Office Macro Security Registry Modifications
- Multi-Base64 Decoding Attempt from Suspicious Location
- Network Connection via Compiled HTML File
- Network Traffic to Rare Destination Country
- Potential Execution via FileFix Phishing Attack
- Potential Hex Payload Execution via Command-Line
- Potential Hex Payload Execution via Common Utility
- Potential Masquerading as Business App Installer
- Potential Notepad Markdown RCE Exploitation
- Potential Widespread Malware Infection Across Multiple Hosts
- Process Activity via Compiled HTML File
- Remote Desktop File Opened from Suspicious Path
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a WebDav Share
- Suspicious Execution from INET Cache
- Suspicious Execution from VS Code Extension
- Suspicious Execution via Microsoft Office Add-Ins
- Suspicious HTML File Creation
- Suspicious macOS MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious PDF Reader Child Process
- Suspicious Troubleshooting Pack Cabinet Execution
- Unusual Base64 Encoding/Decoding Activity
- Unusual Execution via Microsoft Common Console File
- Unusual Windows Path Activity
- Windows Script Execution from Archive
Splunk 47 rules
- 3CXDesktopApp.exe Execution (EDR)
- 3CXDesktopApp.exe Execution (Sysmon)
- 3CXDesktopApp.exe Execution (Windows Event Log)
- Batch File Write to System32
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Command Line Spawned by Archive Utility - Windows (Sysmon)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (EDR)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Sysmon)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Windows Event Log)
- Drop IcedID License dat
- Explorer Child Process with Suspicious Command Line Padding (Sysmon)
- ISO File in Temp Folder (Windows Event Log)
- ISO Image Mounted - Windows (PowerShell)
- ISO Image Mounted - Windows (Windows Event Log)
- Malicious Document Execution (Sysmon)
- Malicious Document Execution (Windows Event Log)
- O365 SharePoint Malware Detection
- O365 Threat Intelligence Suspicious File Detected
- Office Spawns Suspicious Child Process (Sysmon)
- Office Spawns Suspicious Child Process (Windows Event Log)
- Rare executable from Microsoft Office (Sysmon)
- Rare executable from Microsoft Office (Windows Event Log)
- Rare Process Execution (Sysmon)
- Rare Process Execution (Windows Event Log)
- Single Letter Process On Endpoint
- Suspicious Process Executed From Container File
- Symbolic OR Hard File Link Created (PowerShell)
- Symbolic OR Hard File Link Created (Windows Event Log)
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Package Installation Success
- Windows AppX Deployment Unsigned Package Installation
- Windows Binary Execution from an Archive
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Developer-Signed MSIX Package Installation
- Windows EFI Volume Mount Attempt Via Mountvol
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows MSIX Package Interaction
- Windows Mustang Panda USB Tool Execution
- Windows NorthStar C2 Agent Execution
- Windows PowerShell Script From WindowsApps Directory
- Windows Suspect Process With Authentication Traffic
- Windows Suspicious QEMU Execution
- Windows Universal Data Link File Creation
- Windows User Execution Malicious URL Shortcut File
Kusto 7 rules
- Cisco SE - Dropper activity on host
- Cisco SE - Generic IOC
- Cisco SE - Malware execusion on host
- Cisco SE High Events Last Hour
- Critical Severity Detection
- Malware Detected
- Microsoft COVID-19 file hash indicator matches
YARA-L 3 rules
- AWS GuardDuty Malicious Or Suspicious File Executed
- Google Workspace Malicious File Downloaded
- High Risk User Download Executable From Macro