User Execution T1204
Tactic: Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.
Events covered
46 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 326 rules share fields, values, and exclusions.
Fields filtered most (192 distinct)
These fields appear most often in rule filters.
Top indicator values (2478 distinct)
These values appear most often in rule predicates.
Exclusions (976 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 61 rules
- Antivirus - Hacktool Signature
- AppLocker Application Would Have Been Blocked
- AppLocker Prevented Application or Script from Running
- Arbitrary Shell Command Execution Via Settingcontent-Ms
- CLR DLL Loaded Via Office Applications
- DarkSide Ransomware Pattern
- DotNET Assembly DLL Loaded Via Office Application
- Download From Suspicious TLD - Blacklist
- Download From Suspicious TLD - Whitelist
- Droppers Exploiting CVE-2017-11882
- Edge abuse for payload download via console
- Edge/Chrome headless feature abuse for payload download
- Exploit for CVE-2017-0261
- Exploit for CVE-2017-8759
- File With Uncommon Extension Created By An Office Application
- FileFix - Command Evidence in TypedPaths
- Flash Player Update from Suspicious Location
- GAC DLL Loaded Via Office Applications
- HackTool - LittleCorporal Generated Maldoc Injection
- Kapeka Backdoor Loaded Via Rundll32.EXE
- macOS Gatekeeper User Override
- macOS XProtect Malware Detection
- Microsoft Excel Add-In Loaded
- Microsoft Excel Add-In Loaded From Uncommon Location
- Microsoft VBA For Outlook Addin Loaded Via Outlook
- Microsoft Word Add-In Loaded
- MMC Executing Files with Reversed Extensions Using RTLO Abuse
- New Application in AppCompat
- Payload Decoded and Decrypted via Built-in Utilities
- Potential ClickFix Execution Pattern - Registry
- Potential Maze Ransomware Activity
- Potential Snatch Ransomware Activity
- Potential Suspicious Browser Launch From Document Reader Process
- Potentially Suspicious WebDAV LNK Execution
- PrinterNightmare Mimikatz Driver Name
- Remote DLL Load Via Rundll32.EXE
- Successful MSIX/AppX Package Installation
- Suspicious Binaries and Scripts in Public Folder
- Suspicious Binary In User Directory Spawned From Office Application
- Suspicious ClickFix/FileFix Execution Pattern
- Suspicious Deno File Written from Remote Source
- Suspicious Execution via macOS Script Editor
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
- Suspicious FileFix Execution Pattern
- Suspicious LNK Command-Line Padding with Whitespace Characters
- Suspicious Microsoft Office Child Process
- Suspicious Microsoft Office Child Process - MacOS
- Suspicious Outlook Child Process
- Suspicious Space Characters in RunMRU Registry Path - ClickFix
- Suspicious Space Characters in TypedPaths Registry Path - FileFix
- Suspicious Startup Folder Persistence
- Suspicious WMIC Execution Via Office Process
- Suspicious WmiPrvSE Child Process
- Symlink Etc Passwd
- TanStack Supply-Chain Attack Execution Indicators - Linux
- TanStack Supply-Chain Attack Execution Indicators - Windows
- Ursnif Malware C2 URL Pattern
- VBA DLL Loaded Via Office Application
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- Windows MSIX Package Support Framework AI_STUBS Execution
Elastic 110 rules
- Anomalous Process For a Windows Population
- Anomalous Windows Process Creation
- Attempt to Mount a Remote WebDav Share
- Base64 Decoded Payload Piped to Interpreter
- Base64 or Xxd Decode Argument Evasion
- Base64 Shebang Payload Decoded via Built-in Utility
- Command Shell Execution from Untrusted Origin
- Creation of SettingContent-ms Files
- Decoded or Decrypted Payload Written to Suspicious Directory
- Decoded Payload Piped to Interpreter
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Decoy Document Creation via Curl
- Decoy file Open via Preview App
- Disk Image Download and Mount via Hdiutil
- DLL Loaded from WebDav Share
- DNS Query to Suspicious Top Level Domain
- DNS Request by Recently Created Executable
- DNS Request by Suspicious Process Executable
- Downloaded Shortcut Files
- Downloaded URL Files
- Elastic Defend Alert Followed by Telemetry Loss
- Embedded Executable via Windows Shortcut File
- Encoded Payload Detected via Defend for Containers
- Evasion via File Name Masquerading
- Executable File Creation with Multiple Extensions
- Executable File Download via Wget
- Execution from a Password Protected Self Extracting Archive
- Execution from Suspicious Directory
- Execution from ZIP File via Explorer
- Execution of a downloaded executable with low or unknown reputation
- Execution of a Downloaded Windows Script
- Execution of a File Dropped by OpenSSL
- Execution of File Written or Modified by Microsoft Office
- File with Right-to-Left Override Character (RTLO) Created/Executed
- File with Suspicious Extension Downloaded
- Gatekeeper Override and Execution
- Google Workspace Object Copied from External Drive with App Consent
- Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
- Initial Access or Execution via Microsoft Office Application
- Initial Access via macOS Installer Package
- Java Dropped and Executed With DNS Lookup
- Linux Payload Decoded and Decrypted via Built-in Utility
- M365 AIR Investigation Signal
- M365 Threat Intelligence Signal
- Malicious File - Detected - Elastic Defend
- Malicious File - Prevented - Elastic Defend
- Malicious Homebrew Initial Access
- Malicious Reputation of Executable Download
- Masquerading Space After Filename
- Microsoft Build Engine Started by an Office Application
- Microsoft Management Console File from Unusual Path
- MS Office Macro Security Registry Modifications
- Multi-Base64 Decoding Attempt from Suspicious Location
- Network Connection via Compiled HTML File
- Network Traffic to Rare Destination Country
- Node.js Pre or Post-Install Script Execution
- Payload Decoded and Decrypted via Built-In Utilities
- Potential ClickFix Attack via Base64 Decoded Payload
- Potential Decoy Document via Open
- Potential Decoy Document via User Execution
- Potential Execution via Clickfix Phishing
- Potential Execution via FileFix Phishing Attack
- Potential Execution via LNK Stomping
- Potential Fake CAPTCHA Phishing Attack
- Potential Hex Payload Execution via Command-Line
- Potential Hex Payload Execution via Common Utility
- Potential Masquerading as Business App Installer
- Potential Notepad Markdown RCE Exploitation
- Potential Widespread Malware Infection Across Multiple Hosts
- Process Activity via Compiled HTML File
- Remote Desktop File Opened from Suspicious Path
- Script Execution from WebDav
- Shell Execution via Windows Shortcut File
- Shortcut File Modification via Macro Enabled Document
- Spike in host-based traffic
- Suspicious Apple Mail Rule Plist Modification
- Suspicious Base64 String Command-line
- Suspicious Command Execution via Windows Run
- Suspicious Communication via Mail Protocol
- Suspicious Descendant Process Execution via Windows Run
- Suspicious DNS Query from Mounted Virtual Disk
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a WebDav Share
- Suspicious Execution from INET Cache
- Suspicious Execution from VS Code Extension
- Suspicious Execution via Microsoft Common Console
- Suspicious Execution via Microsoft Office Add-Ins
- Suspicious Execution via Script Editor
- Suspicious HTML File Creation
- Suspicious macOS MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious OpenSSL Execution via macOS Application
- Suspicious PDF Reader Child Process
- Suspicious Powershell via Windows Power User Menu
- Suspicious Python Script Interpreter
- Suspicious Script or Process Execution from Mounted Device
- Suspicious Shortcut File Overwrite
- Suspicious Troubleshooting Pack Cabinet Execution
- Suspicious Windows Shortcut File Creation or Modification
- Suspicious xdg-open Command Execution
- Unsigned DLL from Suspicious Directory
- Untrusted Process Execution with Invalid Plist or Code Signature
- Unusual Base64 Encoding/Decoding Activity
- Unusual Execution via Microsoft Common Console File
- Unusual Windows Path Activity
- VScode Extension Install via URI Handler
- Windows Command Shell Spawned via Microsoft Office
- Windows Script Execution from Archive
- Windows Shortcut File Embedded Object Execution
- XDG-Open Command Execution
Splunk 96 rules
- 3CXDesktopApp.exe Execution (Sysmon)
- 3CXDesktopApp.exe Execution (Windows Event Log)
- ASL AWS ECR Container Upload Outside Business Hours
- ASL AWS ECR Container Upload Unknown User
- AWS ECR Container Scanning Findings High
- AWS ECR Container Scanning Findings Low Informational Unknown
- AWS ECR Container Scanning Findings Medium
- AWS ECR Container Upload Outside Business Hours
- AWS ECR Container Upload Unknown User
- AWS Lambda UpdateFunctionCode
- Batch File Write to System32
- Cisco Isovalent - Non Allowlisted Image Use
- Cisco Isovalent - Pods Running Offensive Tools
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Cisco Secure Firewall - Lumma Stealer Activity
- Clop Common Exec Parameter
- Command Line Spawned by Archive Utility - Windows (Sysmon)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log)
- Conti Common Exec parameter
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Sysmon)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Windows Event Log)
- Detect Rare Executables
- Drop IcedID License dat
- Executable Process from Suspicious Folder (PowerShell)
- Executable Process from Suspicious Folder (Sysmon)
- Executable Process from Suspicious Folder (Windows Event Log)
- Explorer Child Process with Suspicious Command Line Padding (Sysmon)
- ISO File in Temp Folder (Windows Event Log)
- ISO Image Mounted - Windows (PowerShell)
- ISO Image Mounted - Windows (Windows Event Log)
- Kubernetes Anomalous Inbound Network Activity from Process
- Kubernetes Anomalous Inbound Outbound Network IO
- Kubernetes Anomalous Inbound to Outbound Network IO Ratio
- Kubernetes Anomalous Outbound Network Activity from Process
- Kubernetes Anomalous Traffic on Network Edge
- Kubernetes Create or Update Privileged Pod
- Kubernetes DaemonSet Deployed
- Kubernetes Falco Shell Spawned
- Kubernetes newly seen TCP edge
- Kubernetes newly seen UDP edge
- Kubernetes Node Port Creation
- Kubernetes Pod Created in Default Namespace
- Kubernetes Pod With Host Network Attachment
- Kubernetes Previously Unseen Container Image Name
- Kubernetes Previously Unseen Process
- Kubernetes Process Running From New Path
- Kubernetes Process with Anomalous Resource Utilisation
- Kubernetes Process with Resource Ratio Anomalies
- Kubernetes Shell Running on Worker Node
- Kubernetes Shell Running on Worker Node with CPU Activity
- Kubernetes Unauthorized Access
- Linux Ghostscript Exploitation
- Malicious Document Execution (Sysmon)
- Malicious Document Execution (Windows Event Log)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Sysmon)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Windows Event Log)
- O365 SharePoint Malware Detection
- O365 Threat Intelligence Suspicious File Detected
- Office Spawns Suspicious Child Process (Sysmon)
- Office Spawns Suspicious Child Process (Windows Event Log)
- Potential CVE-2024-21413: Outbound SMB from Outlook (Sysmon)
- Potential CVE-2024-21413: Outbound SMB from Outlook (Windows Event Log)
- Process Executed from Downloads Folder - Windows (Sysmon)
- Process Executed from Downloads Folder - Windows (Windows Event Log)
- Rare executable from Microsoft Office (Sysmon)
- Rare executable from Microsoft Office (Windows Event Log)
- Rare Process Execution (Sysmon)
- Rare Process Execution (Windows Event Log)
- Revil Common Exec Parameter
- Risk Rule for Dev Sec Ops by Repository
- Single Letter Process On Endpoint
- Suspicious Process Executed From Container File
- Symbolic OR Hard File Link Created (PowerShell)
- Symbolic OR Hard File Link Created (Windows Event Log)
- WebDAV LNK Execution (Sysmon)
- WebDAV LNK Execution (Windows Event Log)
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Package Installation Success
- Windows AppX Deployment Unsigned Package Installation
- Windows Binary Execution from an Archive
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Developer-Signed MSIX Package Installation
- Windows EFI Volume Mount Attempt Via Mountvol
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows ISO LNK File Creation
- Windows MSIX Package Interaction
- Windows Mustang Panda USB Tool Execution
- Windows NorthStar C2 Agent Execution
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell Script From WindowsApps Directory
- Windows Suspect Process With Authentication Traffic
- Windows Suspicious QEMU Execution
- Windows Universal Data Link File Creation
- Windows User Execution Malicious URL Shortcut File
Kusto 42 rules
- Acronis - Multiple Endpoints Accessing Malicious URLs
- Audit policy manipulation using auditpol utility
- AWSCloudTrail - Successful API executed from a Tor exit node
- Cisco SE - Dropper activity on host
- Cisco SE - Generic IOC
- Cisco SE - Malware execusion on host
- Cisco SE High Events Last Hour
- Common Event Format (CEF) via AMA - Critical Severity Detection
- CyberArkEPM - Attack attempt not blocked
- CyberArkEPM - Multiple attack types
- CyberArkEPM - Possible execution of Powershell Empire
- CyberArkEPM - Process started from different locations
- CyberArkEPM - Renamed Windows binary
- CyberArkEPM - Uncommon process Internet access
- CyberArkEPM - Uncommon Windows process started from System folder
- CyberArkEPM - Unexpected executable extension
- CyberArkEPM - Unexpected executable location
- Dataverse - Malware found in SharePoint document management site
- Dataverse - TI map URL to DataverseActivity
- Detect .NET runtime being loaded in JScript for code execution
- Detect Malicious Teams Message
- Egress Defend - Dangerous Attachment Detected
- Egress Defend - Dangerous Link Click
- High severity malicious activity detected
- iboss - Malware Detected
- Insider Risk_High User Security Alert Correlations
- Insider Risk_High User Security Incidents Correlation
- Insider Risk_Risky User Access By Application
- KnowBe4 Defend - Dangerous Attachment Detected
- KnowBe4 Defend - Dangerous Link Click
- Known Malware Detected
- Malware Detected
- Medium severity malicious activity detected
- Microsoft COVID-19 file hash indicator matches
- Netskope - WebTransaction Error Detection
- Network endpoint to host executable correlation
- SonicWall - Capture ATP Malicious File Detection
- Suspicious office child process created
- Suspicious Process Injection from Office application
- Threats detected by ESET
- Threats detected by Eset
- VTI - High Severity SHA1 Collision Detection
YARA-L 5 rules
- AWS GuardDuty Malicious Or Suspicious File Executed
- AWS Successful API From Tor Exit Node
- GCP Successful API Call From Tor Exit Node
- Google Workspace Malicious File Downloaded
- High Risk User Download Executable From Macro
Panther 12 rules
- AppOmni Alert Passthrough
- AWS command executed on the command line
- AWS EC2 Image Monitoring
- Gsuite Attachments Downloaded from Spam Email
- Gsuite Link Clicked in Spam Email
- Malicious Content Detected
- Malware Detected in Email
- Proofpoint Active Threat Campaign Detected
- Proofpoint Malware Detected
- Proofpoint Multiple Threats Detected
- Proofpoint Virus Detected
- Slack Potentially Malicious File Shared