1200KM / detection
T1546 Event Triggered Execution — Detection Rules
Detection workspace for T1546 Event Triggered Execution: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- New Outlook Macro Created · test · medium · {"category":"file_event","product":"windows"}
- Suspicious Outlook Macro Created · test · high · {"category":"file_event","product":"windows"}
- Suspicious Get-Variable.exe Creation · test · high · {"product":"windows","category":"file_event"}
- Control Panel Items · test · high · {"product":"windows","category":"process_creation"}
- COM Hijack via Sdclt · test · high · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting · test · high · {"category":"registry_set","product":"windows"}
- Outlook Macro Execution Without Warning Setting Enabled · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0010 Behavioral Detection of Event Triggered Execution Across Platforms
AN0024 Analytic 0024
Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.
AN0025 Analytic 0025
Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers.
AN0026 Analytic 0026
Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents.
AN0027 Analytic 0027
Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts.
AN0028 Analytic 0028
Correlates Power Automate or similar logic app workflows triggered by SaaS file uploads or email rules with data forwarding or anomalous access patterns.
AN0029 Analytic 0029
Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.