1200KM / detection
T1080 Taint Shared Content — Detection Rules
Detection workspace for T1080 Taint Shared Content: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0471 Detection of Tainted Content Written to Shared Storage
AN1298 Analytic 1298
Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity.
AN1299 Analytic 1299
Detects script or binary modification within shared NFS/SMB directories followed by process execution from those paths.
AN1300 Analytic 1300
Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app).
AN1301 Analytic 1301
Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions.
AN1302 Analytic 1302
Detects embedded macros or scripts added to shared documents or use of external references to execute code.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.