1200KM / detection
T1027.017 SVG Smuggling — Detection Rules
Detection workspace for T1027.017 SVG Smuggling: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0510 Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior
AN1407 Analytic 1407
Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection.
AN1408 Analytic 1408
Detects downloaded SVG files followed by execution of browser processes or tools like xdg-open, and rapid follow-on network connections or process spawns to interpreters like python or bash.
AN1409 Analytic 1409
Detects SVGs downloaded via browser that invoke AppleScript, osascript, or JavaScriptCore processes, followed by network egress or file drop to LaunchAgents or ~/Library.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1027.017 simulation workspace
- File Creation · DC0039
- File Modification · DC0061
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.