{"id":"T1027.006","name":"HTML Smuggling","url":"https://attack.mitre.org/techniques/T1027/006","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0313","stix_id":"x-mitre-detection-strategy--a8067c32-46d5-426e-9c1a-e91d360be83d","name":"Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop","url":"https://attack.mitre.org/detectionstrategies/DET0313","analytics":[{"id":"AN0872","stix_id":"x-mitre-analytic--0cb02d2e-dcea-4195-80e7-81ec29b4d546","name":"Analytic 0872","description":"Detection of browser-based or email client-driven file creation (often from temp directories) following navigation to or execution of HTML files containing JavaScript Blob APIs or base64 Data URLs, with follow-on execution of the dropped payload. Leveraging Sysmon EventID 15 to inspect Zone.Identifier ADS for HostUrl/ReferrerUrl indicators (e.g., HostUrl=about:internet). Optional: absence of a large HTTP download record for the same URL/client in proxy logs (suggests local assembly)","url":"https://attack.mitre.org/detectionstrategies/DET0313#AN0872","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:detection","channel":"App reputation telemetry","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"edr-detection"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"}],"mutable_elements":[{"field":"TimeWindow","description":"Time range between HTML file open and file drop + execution (e.g., 1–10 minutes)"},{"field":"DroppedFileExtensionWatchlist","description":"Tunable list of file extensions of interest (e.g., .js, .hta, .exe)"},{"field":"ParentProcessName","description":"Expected processes that may drop files (e.g., browser, Outlook); tune for normal behavior"}],"live":true,"detection_strategies":["DET0313"],"techniques":["T1027.006"]},{"id":"AN0873","stix_id":"x-mitre-analytic--30ae2215-5dd5-4ef2-82bd-965781ef1f42","name":"Analytic 0873","description":"Detection of browser-based downloads from HTML sources that trigger file creation in temp or user directories followed by execution of new files within short timeframes and suspicious parent-child lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0313#AN0873","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"file_events","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"DownloadPathRegex","description":"Regular expressions for common download paths (e.g., /tmp/, ~/Downloads/)"},{"field":"ExecutableTriggerWindow","description":"Tunable range for follow-up process execution from dropped file (e.g., 5–15 minutes)"}],"live":true,"detection_strategies":["DET0313"],"techniques":["T1027.006"]},{"id":"AN0874","stix_id":"x-mitre-analytic--5f8b5ef5-8b4a-4713-a694-dc0746669a73","name":"Analytic 0874","description":"Detection of HTML-based downloads via Safari/Chrome that create obfuscated files (e.g., .zip, .app, .js) in user directories and are followed by suspicious executions from preview or launch services.","url":"https://attack.mitre.org/detectionstrategies/DET0313#AN0874","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"File Events","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"gatekeeper/quarantine database","channel":"LaunchServices quarantine","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"gatekeeper-quarantine-database"}],"mutable_elements":[{"field":"QuarantineFlagCheck","description":"Whether downloaded file has a quarantine flag and is bypassed via Gatekeeper"},{"field":"BlobKeywordAlertList","description":"JavaScript strings that may indicate smuggling: msSaveBlob, download.href, createObjectURL"}],"live":true,"detection_strategies":["DET0313"],"techniques":["T1027.006"]}],"live":true,"version":"1.0","techniques":["T1027.006"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}