Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0257 — Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files
DET0257

Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0712 Analytic 0712
Windows

Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=15
[WatchedExtensions] Adjust monitored file types (e.g., .iso, .vhd, .zip, .gz, .rar) based on enterprise usage
[TimeWindow] Defines correlation window between extraction/mount and first execution of inner files
[TrustedExtractionTools] Whitelist known enterprise archivers and deployment mechanisms to reduce false positives

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0257
STIX ID
x-mitre-detection-strategy--2556841e-474a-45c0-b827-4f5db6dcca31
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.