Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0180 — Detection Strategy for T1547.009 – Shortcut Modification (Windows)
DET0180

Detection Strategy for T1547.009 – Shortcut Modification (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0510 Analytic 0510
Windows

Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=15
[TargetPathRegex] Tunable regex to flag suspicious shortcut target paths (e.g., temp folder, base64 in target, unusual executable names)
[TimeWindow] Time window used to correlate shortcut creation with process execution (e.g., 5-minute window)
[UserContextScope] Filter for expected administrative installs versus end-user initiated shortcut creation
[ZoneIdentifierThreshold] Configurable value to filter LNK files tagged with external source markers (e.g., ZoneId=3 for Internet)

Detected Techniques

1

Details

MITRE ID
DET0180
STIX ID
x-mitre-detection-strategy--300931b1-bd28-4e91-ba6e-585f3563e8e4
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.