User Execution T1204

Tactic: Execution

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Events covered

46 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 22DNSEvent (DNS query)
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Defender-DeviceEventsCreateRemoteThreadApiCallCreateRemoteThread API call
Defender-DeviceEventsQueueUserApcRemoteApiCallRemote APC queued (QueueUserApc)
Defender-DeviceEventsSetThreadContextRemoteApiCallRemote thread context change (SetThreadContext)
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceFileEventsFileRenamedFile renamed
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceNetworkEventsConnectionSuccessConnection succeeded
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
Defender-MessageEventsanyTeams message processed
Defender-MessageUrlInfoanyTeams message URL observed
ESFexecProcess Execution
ESFforkProcess Fork
ESFcreateFile or Directory Create
ESFwriteFile Write
AppLockerEvent ID 8003RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8004FilePathBuffer was prevented from running.
AppLockerEvent ID 8006FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8007FilePathBuffer was prevented from running.
AppLockerEvent ID 8021PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8022PackageBuffer was prevented from running.
AppLockerEvent ID 8024PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8025PackageBuffer was prevented from running.
AppXDeployment-ServerEvent ID 400Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path finished successfully.
AppXDeployment-ServerEvent ID 603Started deployment DeploymentOperation operation on a package with main parameter Path and Options Flags and FlagsHigh.
AppXDeployment-ServerEvent ID 854Successfully added the following uri(s) to be processed: Path.
AppXDeployment-ServerEvent ID 855Finished resolving action lists.
AppxPackagingOMEvent ID 171The reader was created successfully for app package packageFullName.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 326 rules share fields, values, and exclusions.

Fields filtered most (192 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name100eq 66, in 22, regex_match 16, starts_with 13, wildcard 9, contains 2, cross_field_compare 2, ends_with 1, ne 1cmd.exe, base64, bash, cscript.exe, base16
EventType72eq 66, in 8, ne 4exec, start, creation, ProcessRollup2, deletion
event.type58eq 57, ne 2start, creation, deletion, denied, allowed
CommandLine55contains 31, regex_match 12, wildcard 12, in 5, ends_with 3, match 2, eq 1, length_compare 1, starts_with 1#, (?i)DavWWWRoot, (?i)PCWDiagnostic|invoke, (?i)cab|diagcab, *\\*@*,*
Image54ends_with 30, wildcard 10, starts_with 8, contains 7, in 3, is_not_null 2, regex_match 2, eq 1\excel.exe, \mspub.exe, ?:\users\*\downloads\*, \onenote.exe, \cmd.exe
parent_process_name49eq 27, regex_match 14, in 7, ends_with 1explorer.exe, 7zfm.exe, cmd.exe, excel.exe, winrar.exe
EventID47eq 43, in 3, regex_match 11, 4688, 4104, malicious_file, 4663
host.os.type43eq 42, in 1
process.args38eq 21, wildcard 19, in 14, starts_with 11, contains 9, ends_with 2, regex_match 1-base64, -a, *-*d*, -d, --d
ParentImage34ends_with 17, contains 8, is_not_null 4, eq 3, cross_field_compare 1, in 1, match 1, starts_with 1\eqnedt32.exe, \explorer.exe, \, \excel.exe, \msaccess.exe
TargetFilename20wildcard 10, contains 7, ends_with 4, in 1, regex_match 1, starts_with 1.bat, .cmd, .dll, /dev/shm/*, /home/*/*
process.args_count16ge 6, eq 5, le 3, gt 1, lt 12, 1, 4, 3, 5
OriginalFileName15eq 13, wildcard 2cmd.exe, powershell.exe, powershell_ise.exe, autoit*.exe, popupwrapper.exe
file.extension15eq 13, in 2lnk, exe, url, appinstaller, application
sourcetype15eq 14, in 1aws:cloudtrail, aws:asl, cisco:isovalent:processexec, o365:management:activity, cisco:nvm:flowdata

Top indicator values (2478 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
481078
event.typeeq
creation
753
EventTypeeq
start
27391
EventTypeeq
exec
26576
process_nameeq
powershell.exe
21184
process_nameeq
cmd.exe
19121
process_nameeq
mshta.exe
1684
process_nameeq
wscript.exe
1483
process_nameeq
openssl
1228
process_nameeq
cscript.exe
1167
process_nameeq
pwsh.exe
1177
process_nameeq
rundll32.exe
10126
process_nameeq
msiexec.exe
946
parent_process_nameeq
explorer.exe
1651
EventIDeq
1
13241
EventIDeq
4688
13317
process_namestarts_with
python
1071
process_namestarts_with
perl
836
process_namestarts_with
ruby
836
process.argseq
-c
9107
process.argseq
enc
916
process.argseq
-e
846
process.argsin
-d
914
process.argsin
-base64
811
process_namein
bash
9202
process_namein
sh
9197
process_namein
zsh
9196
spaneq
10s
99
Imageends_with
\excel.exe
716
countgt
5
714

Exclusions (976 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
9
process_nameeq
rundll32.exe
7
process_nameeq
cmd.exe
6
process_nameeq
powershell.exe
4
Imagewildcard
?:\program files (x86)\*.exe
5
Imagewildcard
?:\program files\*.exe
5
CurrentDirectorywildcard
/opt/zeek
3
CurrentDirectorywildcard
/proc/self/fd/*/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek_old_install
3
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/opt/zeek
3
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/usr/local/zeek
3
ParentCommandLinecontains
extendedglob
3
parent_process_nameeq
zsh
3
parent_process_namestarts_with
python
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 61 rules

Elastic 110 rules

Splunk 96 rules

Kusto 42 rules

YARA-L 5 rules

Panther 12 rules