1200KM / detection
T1204.001 Malicious Link — Detection Rules
Detection workspace for T1204.001 Malicious Link: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Symlink Etc Passwd · test · high · {"product":"linux"}
- Suspicious Execution via macOS Script Editor · test · medium · {"category":"process_creation","product":"macos"}
- Suspicious ClickFix/FileFix Execution Pattern · experimental · high · {"category":"process_creation","product":"windows"}
- Potential ClickFix Execution Pattern - Registry · experimental · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0066 User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
AN0178 Analytic 0178
Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs.
AN0179 Analytic 0179
Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after.
AN0180 Analytic 0180
Behavioral chain: (1) Safari/Chrome/Firefox/Office handles a URL; unified logs show open/click or LSQuarantine assignment, (2) outbound connection to untrusted domain, (3) a new file appears in ~/Downloads or /private/var/folders/* with quarantine flag.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1204.001 simulation workspace
- File Creation · DC0039
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Turla · G0010
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- MuddyWater · G0069
- Cobalt Group · G0080
- APT38 · G0082
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Wizard Spider · G0102
- Mofang · G0103
- Windshift · G0112
- Evilnum · G0120
- Sidewinder · G0121
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- Earth Lusca · G1006
- EXOTIC LILY · G1011
- LuminousMoth · G1014
- TA2541 · G1018
- Mustard Tempest · G1020
- Saint Bear · G1031
- Daggerfly · G1034
- Winter Vivern · G1035
- TA577 · G1037
- TA578 · G1038
- RedCurl · G1039
- Contagious Interview · G1052
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.