Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0066 — User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
DET0066

User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0178 Analytic 0178
Windows

Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=11 NSM:Flow Suspicious URL patterns, uncommon TLDs, short-lived domains, URL shorteners; HTTP method GET/POST
[TimeWindow] Correlation window (e.g., 15m) between link click / first egress / file write.
[BrowserParents] Processes considered link sources: chrome.exe, msedge.exe, firefox.exe, winword.exe, outlook.exe, teams.exe.
[UserPaths] User-writable directories to monitor (%USERPROFILE%\Downloads, %TEMP%, %APPDATA%\*, OneDrive caches).
[SuspiciousTLDs] High-risk TLD and domain list (e.g., .top .xyz .monster; newly observed domains/NOD).
[AllowedCDNs] Corporate CDNs/update hosts to reduce false positives.
AN0179 Analytic 0179
Linux

Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after.

auditd:SYSCALL execve: Execs of chromium, google-chrome, firefox, libreoffice with http(s) in cmdline auditd:SYSCALL open,creat,rename: Writes in $HOME/Downloads, /tmp, ~/.cache with exe/script/archive/office extensions NSM:Flow Suspicious URL patterns, uncommon TLDs, URL shorteners
[TimeWindow] Typical 10–20m between click and write.
[UserPaths] $HOME/Downloads, /tmp, ~/.cache, ~/.local/share.
[HighRiskExtensions] exe, elf, sh, js, py, jar, iso, img, zip, rar, xlsm, docm, xll.
[DomainRiskScore] Heuristic or TI score threshold for domains.
AN0180 Analytic 0180
macOS

Behavioral chain: (1) Safari/Chrome/Firefox/Office handles a URL; unified logs show open/click or LSQuarantine assignment, (2) outbound connection to untrusted domain, (3) a new file appears in ~/Downloads or /private/var/folders/* with quarantine flag.

macos:unifiedlog open URL|clicked link|LSQuarantineAttach NSM:Connections New outbound connection from Safari/Chrome/Firefox/Word fs:fsevents Create in /Users/*/Downloads or /private/var/folders/* with quarantine attribute
[TimeWindow] 10–30m correlation.
[QuarantinePolicy] Alert when com.apple.quarantine missing on newly downloaded executables.
[SuspiciousTLDs] Org-specific risky domains/TLDs.

Detected Techniques

1

Details

MITRE ID
DET0066
STIX ID
x-mitre-detection-strategy--b977bf63-8fe2-4538-b4f2-0098fe26d67b
Analytics
3
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.