Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0899 — Detect Social Engineering
DET0899

Detect Social Engineering

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN2033 Analytic 2033
Office Suite

Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.

m365:unified MailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet m365:exchange External sender message followed by user action involving links or attachments m365:teams External chat request or new tenant communication preceding approval activity
[ActionAfterMessageWindow] Time window between inbound communication and sensitive action
[TrustedDomainAllowlist] Known legitimate vendors or partner domains
[ApprovalAmountThreshold] Monetary threshold for finance workflows
AN2034 Analytic 2034
SaaS

Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.

saas:okta user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize saas:slack xternal DM or workspace invite preceding credential or approval actions saas:zoom Unexpected contact interaction preceding follow-on admin requests
[RequesterNoveltyDays] How long since requestor last interacted with user
[GeoVelocityThreshold] Distance/time anomaly for follow-on login
[AfterHoursDefinition] Organization-specific off-hours period
AN2035 Analytic 2035
Windows

Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=11
[EmailToExecutionWindow] Time between message delivery and process launch
[OfficeChildProcessAllowlist] Approved Office child process patterns
[NewLogonWindow] Time after credential prompt to monitor new sessions
AN2036 Analytic 2036
macOS

Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.

macos:unifiedlog Execution of osascript, sh, bash, zsh, installer, open NSM:Connections Outbound connection after script or installer launch macos:unifiedlog Recent download opened or executed
[DownloadToExecutionWindow] Time between download and launch
[InstallerParentAllowlist] Legitimate software deployment parents
AN2037 Analytic 2037
Linux

Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.

NSM:Connections Outbound connection after script or installer launch auditd:EXECVE execve of curl,wget,bash,sh,python with piped or remote content auditd:PATH odification of ~/.ssh/authorized_keys or credential files
[RemoteScriptExecutionPatterns] Organization-specific admin automation patterns to exclude
[TicketToExecutionWindow] Time from help desk/chat event to command execution

Detected Techniques

1

Details

MITRE ID
DET0899
STIX ID
x-mitre-detection-strategy--48923678-0fb6-4d14-986b-2f6adeb8c421
Analytics
5
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.