1200KM / detection
T1480.002 Mutual Exclusion — Detection Rules
Detection workspace for T1480.002 Mutual Exclusion: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0132 Detection of Mutex-Based Execution Guardrails Across Platforms
AN0372 Analytic 0372
Adversary-created named mutex using system APIs (e.g., CreateMutexW) followed by conditional process termination or alternate code path indicating malware avoiding reinfection.
AN0373 Analytic 0373
File lock acquired via open() + flock() or lockf() on predictable path (e.g., /tmp/.lock123) followed by conditional early exit or divergent process behavior.
AN0374 Analytic 0374
User-mode application uses flock() or NSDistributedLock to gain exclusive access to a resource file (e.g., /tmp/guard.lock), conditional logic alters execution if already locked.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1480.002 simulation workspace
- File Access · DC0055
- File Creation · DC0039
- OS API Execution · DC0021
- Process Creation · DC0032
- Process Termination · DC0033
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.