// MITRE ATT&CK
T1204 · User Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from fo...
¿Cómo detectarlo y mitigarlo?
La detección de User Execution parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (5)
T1204.001
Malicious Link T1204.002
Malicious File T1204.003
Malicious Image T1204.004
Malicious Copy and Paste T1204.005
Malicious Library
Malicious Link T1204.002
Malicious File T1204.003
Malicious Image T1204.004
Malicious Copy and Paste T1204.005
Malicious Library
Técnicas relacionadas
T1053.005
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.