// MITRE ATT&CK
T1204 · User Execution
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from fo...
How to detect & mitigate it
Detecting User Execution starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (5)
T1204.001
Malicious Link T1204.002
Malicious File T1204.003
Malicious Image T1204.004
Malicious Copy and Paste T1204.005
Malicious Library
Malicious Link T1204.002
Malicious File T1204.003
Malicious Image T1204.004
Malicious Copy and Paste T1204.005
Malicious Library
Related techniques
T1053.005
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.