1200KM / detection
T1204 User Execution — Detection Rules
Detection workspace for T1204 User Execution: 7 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Antivirus Hacktool Detection · stable · high · {"category":"antivirus"}
- Payload Decoded and Decrypted via Built-in Utilities · test · medium · {"category":"process_creation","product":"macos"}
- Suspicious Execution via macOS Script Editor · test · medium · {"category":"process_creation","product":"macos"}
- Suspicious Deno File Written from Remote Source · experimental · low · {"category":"file_event","product":"windows"}
- Suspicious Binaries and Scripts in Public Folder · experimental · high · {"category":"file_event","product":"windows"}
- Arbitrary Shell Command Execution Via Settingcontent-Ms · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious WebDAV LNK Execution · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1204 User Execution
SEQUENCE(file_download_or_attachment_open, process_execution FROM downloaded_file) WITHIN 5m -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0478 User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)
AN1314 Analytic 1314
Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage.
AN1315 Analytic 1315
Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s) from the child lineage.
AN1316 Analytic 1316
Cause→effect chain: (1) unified logs show application open/click or crash for Safari/Chrome/Office/Preview/archiver, (2) file write/extraction into ~/Downloads, /private/var/folders/* or ~/Library, (3) parent app spawns osascript/bash/zsh/curl/python or opens a quarantined app with Gatekeeper prompts, (4) network egress from child.
AN1317 Analytic 1317
Cause→effect chain in CI/dev desktops: (1) user triggers container run/pull after opening a doc/link/script, (2) newly created image/container uses unexpected external registry or entrypoint, (3) container starts and immediately egresses to suspicious destinations.
AN1318 Analytic 1318
Cause→effect chain in cloud consoles: (1) user clicks link then invokes instance/image creation via API, (2) instance/image originates from external AMI or unknown image, (3) instance immediately egresses or retrieves payloads.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Container Creation · DC0072
- Container Start · DC0077
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Instance Creation · DC0076
- Instance Start · DC0080
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.