1200KM / detection
T1204.002 Malicious File — Detection Rules
Detection workspace for T1204.002 Malicious File: 27 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Microsoft Office Child Process - MacOS · test · high · {"product":"macos","category":"process_creation"}
- Download From Suspicious TLD - Blacklist · test · low · {"category":"proxy"}
- Download From Suspicious TLD - Whitelist · test · low · {"category":"proxy"}
- Flash Player Update from Suspicious Location · test · high · {"category":"proxy"}
- AppLocker Prevented Application or Script from Running · test · medium · {"product":"windows","service":"applocker"}
- Windows AppX Deployment Full Trust Package Installation · experimental · medium · {"product":"windows","service":"appxdeployment-server"}
- Windows AppX Deployment Unsigned Package Installation · experimental · medium · {"product":"windows","service":"appxdeployment-server"}
- File With Uncommon Extension Created By An Office Application · test · high · {"product":"windows","category":"file_event"}
- Suspicious Startup Folder Persistence · test · high · {"product":"windows","category":"file_event"}
- DotNET Assembly DLL Loaded Via Office Application · test · medium · {"category":"image_load","product":"windows"}
- CLR DLL Loaded Via Office Applications · test · medium · {"category":"image_load","product":"windows"}
- GAC DLL Loaded Via Office Applications · test · high · {"category":"image_load","product":"windows"}
- Microsoft Excel Add-In Loaded From Uncommon Location · test · medium · {"category":"image_load","product":"windows"}
- Microsoft VBA For Outlook Addin Loaded Via Outlook · test · medium · {"category":"image_load","product":"windows"}
- VBA DLL Loaded Via Office Application · test · high · {"category":"image_load","product":"windows"}
- Remote DLL Load Via Rundll32.EXE · test · medium · {"category":"image_load","product":"windows"}
- HackTool - LittleCorporal Generated Maldoc Injection · test · high · {"category":"process_access","product":"windows"}
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · experimental · high · {"category":"process_creation","product":"windows"}
- Windows MSIX Package Support Framework AI_STUBS Execution · experimental · low · {"category":"process_creation","product":"windows"}
- Suspicious Outlook Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Binary In User Directory Spawned From Office Application · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Microsoft Office Child Process · test · high · {"category":"process_creation","product":"windows"}
- Potential Suspicious Browser Launch From Document Reader Process · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious LNK Command-Line Padding with Whitespace Characters · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious WMIC Execution Via Office Process · test · high · {"product":"windows","category":"process_creation"}
- Suspicious WmiPrvSE Child Process · test · high · {"product":"windows","category":"process_creation"}
- New Application in AppCompat · test · informational · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0294 User Execution – Malicious File via download/open → spawn chain (T1204.002)
AN0819 Analytic 0819
User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.
AN0820 Analytic 0820
User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.
AN0821 Analytic 0821
User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT12 · G0005
- APT28 · G0007
- Darkhotel · G0012
- APT30 · G0013
- APT29 · G0016
- admin@338 · G0018
- Naikon · G0019
- Molerats · G0021
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- RTM · G0048
- OilRig · G0049
- APT32 · G0050
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- MuddyWater · G0069
- Dark Caracal · G0070
- APT19 · G0073
- Rancor · G0075
- Gorgon Group · G0078
- DarkHydrus · G0079
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- Gallmaker · G0084
- FIN4 · G0085
- APT39 · G0087
- The White Company · G0089
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Inception · G0100
- Wizard Spider · G0102
- Mofang · G0103
- Whitefly · G0107
- Windshift · G0112
- Indrik Spider · G0119
- Sidewinder · G0121
- Higaisa · G0126
- TA551 · G0127
- Mustang Panda · G0129
- Ajax Security Team · G0130
- Tonto Team · G0131
- Nomadic Octopus · G0133
- Transparent Tribe · G0134
- IndigoZebra · G0136
- Ferocious Kitten · G0137
- Andariel · G0138
- LazyScripter · G0140
- Confucius · G0142
- HEXANE · G1001
- BITTER · G1002
- Earth Lusca · G1006
- Aoqin Dragon · G1007
- SideCopy · G1008
- EXOTIC LILY · G1011
- CURIUM · G1012
- TA2541 · G1018
- Malteiro · G1026
- Saint Bear · G1031
- Star Blizzard · G1033
- Moonstone Sleet · G1036
- RedCurl · G1039
- Storm-1811 · G1046
- Contagious Interview · G1052
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.