1200KM / detection
T1585.001 Social Media Accounts — Detection Rules
Detection workspace for T1585.001 Social Media Accounts: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0851 Detection of Social Media Accounts
AN1983 Analytic 1983
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Spearphishing via Service).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1585.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Cleaver · G0003
- Lazarus Group · G0032
- Sandworm Team · G0034
- APT32 · G0050
- Magic Hound · G0059
- Leviathan · G0065
- Kimsuky · G0094
- Fox Kitten · G0117
- HEXANE · G1001
- EXOTIC LILY · G1011
- CURIUM · G1012
- Scattered Spider · G1015
- Star Blizzard · G1033
- Moonstone Sleet · G1036
- Water Galura · G1050
- Medusa Group · G1051
- Contagious Interview · G1052
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.