1200KM / detection
T1684 Social Engineering — Detection Rules
Detection workspace for T1684 Social Engineering: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0899 Detect Social Engineering
AN2037 Analytic 2037
Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.
AN2035 Analytic 2035
Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.
AN2034 Analytic 2034
Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.
AN2033 Analytic 2033
Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.
AN2036 Analytic 2036
Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Logon Session Creation · DC0067
- Network Connection Creation · DC0082
- Process Creation · DC0032
- User Account Authentication · DC0002
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.