1200KM / detection
T1547.009 Shortcut Modification — Detection Rules
Detection workspace for T1547.009 Shortcut Modification: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Windows Network Access Suspicious desktop.ini Action · test · medium · {"product":"windows","service":"security"}
- New Custom Shim Database Created · test · medium · {"product":"windows","category":"file_event"}
- Creation Exe for Service with Unquoted Path · test · high · {"product":"windows","category":"file_event"}
- Desktop.INI Created by Uncommon Process · test · medium · {"product":"windows","category":"file_event"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0180 Detection Strategy for T1547.009 – Shortcut Modification (Windows)
AN0510 Analytic 0510
Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.