Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0294 — User Execution – Malicious File via download/open → spawn chain (T1204.002)
DET0294

User Execution – Malicious File via download/open → spawn chain (T1204.002)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0819 Analytic 0819
Windows

User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=15
[TimeWindow] Seconds/minutes to correlate file write to child spawn (e.g., 0–5m).
[SuspiciousExtensions] Extensions and double-extension patterns to flag (exe,scr,lnk,pif,cpl,js,vbs,bat,cmd,ps1,hta,iso,lnk->cmd,docm,xlsm,pdf->exe, etc.).
[UserPaths] Paths considered user-controlled (Downloads, Temp, Desktop, profile AppData staging).
[ParentApps] List of user-facing apps that commonly open attachments for your org (reduce FPs or add weight).
[SignerAllowList] Trusted code signers/publishers to suppress benign admin tools.
AN0820 Analytic 0820
macOS

User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.

macos:unifiedlog process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder} macos:endpointsecurity ES_EVENT_TYPE_NOTIFY_CREATE: path under /Users/*/(Downloads|Desktop|Library/*/Containers|Library/Group Containers) AND extension in SuspiciousExtensions
[TimeWindow] Correlation window between file create and exec (e.g., ≤10m).
[QuarantineRequired] Require com.apple.quarantine attribute present on the file for higher fidelity.
[ParentApps] Approved document viewers/editors to anchor lineage.
AN0821 Analytic 0821
Linux

User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.

auditd:SYSCALL open/create/rename: name in (/home/*/Downloads/*|/tmp/*|/run/user/*|/media/*) AND ext in SuspiciousExtensions auditd:SYSCALL execve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser
[TimeWindow] Correlation window for audit events (e.g., ≤5m).
[DesktopParentMap] Map common desktop apps (libreoffice, evince, firefox, chromium) for lineage anchoring.

Detected Techniques

1

Details

MITRE ID
DET0294
STIX ID
x-mitre-detection-strategy--e2023eb5-d813-4a08-985e-e8c998672037
Analytics
3
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.