1200KM / detection
T1204.004 Malicious Copy and Paste — Detection Rules
Detection workspace for T1204.004 Malicious Copy and Paste: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious ClickFix/FileFix Execution Pattern · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious FileFix Execution Pattern · experimental · high · {"category":"process_creation","product":"windows"}
- FileFix - Command Evidence in TypedPaths · experimental · high · {"category":"registry_set","product":"windows"}
- Suspicious Space Characters in RunMRU Registry Path - ClickFix · experimental · high · {"category":"registry_set","product":"windows"}
- Suspicious Space Characters in TypedPaths Registry Path - FileFix · experimental · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0340 User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004
AN0962 Analytic 0962
A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session.
AN0963 Analytic 0963
User pastes a multi-line or one-liner into a terminal (bash/zsh) that downloads/decodes and executes content. Chain: terminal exec of curl/wget/bash/sh with pipe to interpreter or base64-decode → transient file under /tmp|~/.cache → immediate outbound egress.
AN0964 Analytic 0964
User pastes an obfuscated command into Terminal.app/iTerm2 that decodes or downloads code and executes. Detects Terminal/iTerm2 spawning bash/zsh/python with suspicious pipeline/base64 patterns followed by file writes in ~/Library or /tmp and outbound network connections.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1204.004 simulation workspace
- Command Execution · DC0064
- File Creation · DC0039
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.