Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0405 — Detection Strategy for LNK Icon Smuggling
DET0405

Detection Strategy for LNK Icon Smuggling

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1134 Analytic 1134
Windows

Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=15 WinEventLog:Sysmon EventCode=3, 22
[ParentProcessName] Can be tuned to focus on common launcher processes like explorer.exe or winword.exe.
[DestinationIP] Filtered to exclude known good domains and internal IPs to reduce false positives.
[TimeWindow] Time between LNK execution and subsequent suspicious activity may vary based on adversary delay.
[FileExtension] Could be used to focus on .lnk files only or track associated dropped payloads like .dat, .exe, etc.

Detected Techniques

1

Details

MITRE ID
DET0405
STIX ID
x-mitre-detection-strategy--ae3cb4bc-da0a-4e5b-b4ad-96617eccefaf
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.