AN1134
Analytic 1134
Windows
Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=15
WinEventLog:Sysmon
EventCode=3, 22
[ParentProcessName]
Can be tuned to focus on common launcher processes like explorer.exe or winword.exe.
[DestinationIP]
Filtered to exclude known good domains and internal IPs to reduce false positives.
[TimeWindow]
Time between LNK execution and subsequent suspicious activity may vary based on adversary delay.
[FileExtension]
Could be used to focus on .lnk files only or track associated dropped payloads like .dat, .exe, etc.