T1204 User Execution — ATT&CK Technique
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing. While User Execution frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing. Adversaries may also deceive users into performing actions such as: * Enabling Remote Access Tools, allowing direct control of the system to the adversary * Running malicious JavaScript in their browser, allowing adversaries to Steal Web Session Cookies * Downloading and executing malware for User Execution * Coerceing users to copy, paste, and execute malicious code manually For example, tech support scams can be facilitated through Phishing, vishing, or various forms of user interaction. Adversaries can use a combination of these methods, such as spoofing and promoting toll-free numbers or call centers that are used to direct victims to malicious websites, to deliver and execute payloads containing malware or Remote Access Tools.
Detection coverage (37)
- Potential Snatch Ransomware Activity high
- PrinterNightmare Mimikatz Driver Name critical
- Suspicious Execution via macOS Script Editor medium
- DarkSide Ransomware Pattern critical
- Antivirus Hacktool Detection high
- Payload Decoded and Decrypted via Built-in Utilities medium
- Suspicious Deno File Written from Remote Source low
- Suspicious Binaries and Scripts in Public Folder high
- Arbitrary Shell Command Execution Via Settingcontent-Ms medium
- Potentially Suspicious WebDAV LNK Execution medium
- Revil Common Exec Parameter
- AWS Lambda UpdateFunctionCode
- Kubernetes Anomalous Inbound Network Activity from Process
- Kubernetes Anomalous Inbound Outbound Network IO
- Kubernetes Anomalous Inbound to Outbound Network IO Ratio
- Kubernetes Anomalous Outbound Network Activity from Process
- Kubernetes Anomalous Traffic on Network Edge
- Kubernetes Create or Update Privileged Pod
- Kubernetes DaemonSet Deployed
- Kubernetes Falco Shell Spawned
- Kubernetes newly seen TCP edge
- Kubernetes newly seen UDP edge
- Kubernetes Node Port Creation
- Kubernetes Pod Created in Default Namespace
- Kubernetes Pod With Host Network Attachment
- Kubernetes Previously Unseen Container Image Name
- Kubernetes Previously Unseen Process
- Kubernetes Process Running From New Path
- Kubernetes Process with Anomalous Resource Utilisation
- Kubernetes Process with Resource Ratio Anomalies
- Kubernetes Shell Running on Worker Node
- Kubernetes Shell Running on Worker Node with CPU Activity
- Kubernetes Unauthorized Access
- Conti Common Exec parameter
- Clop Common Exec Parameter
- Detect Rare Executables
- Cisco Secure Firewall - Lumma Stealer Activity