{"id":"T1027.017","name":"SVG Smuggling","url":"https://attack.mitre.org/techniques/T1027/017","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0510","stix_id":"x-mitre-detection-strategy--6c59d987-c339-4743-bdb0-0eb21285deb7","name":"Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior","url":"https://attack.mitre.org/detectionstrategies/DET0510","analytics":[{"id":"AN1407","stix_id":"x-mitre-analytic--288a28ac-e1e4-4e7e-9156-d3b975ed45ed","name":"Analytic 1407","description":"Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection.","url":"https://attack.mitre.org/detectionstrategies/DET0510#AN1407","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Threshold between SVG file write and script execution (e.g., < 60s)"},{"field":"ParentProcessWhitelist","description":"Allowlisted script engines that may invoke browsers or JS in benign cases"},{"field":"FileExtensionPattern","description":"Regex or string match for .svg, .svgz, or embedded .svg inside HTML or PDF"}],"live":true,"detection_strategies":["DET0510"],"techniques":["T1027.017"]},{"id":"AN1408","stix_id":"x-mitre-analytic--99bfd95b-256a-4b1d-bf1d-481f47642c15","name":"Analytic 1408","description":"Detects downloaded SVG files followed by execution of browser processes or tools like xdg-open, and rapid follow-on network connections or process spawns to interpreters like python or bash.","url":"https://attack.mitre.org/detectionstrategies/DET0510#AN1408","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound HTTP/S","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TargetPaths","description":"Suspicious write locations such as /tmp/, ~/Downloads/"},{"field":"ExecutionContext","description":"Processes spawned by browsers or svg-viewing apps that invoke interpreters"},{"field":"NetworkDestinations","description":"URLs/IPs contacted post-SVG access – may reflect initial C2"}],"live":true,"detection_strategies":["DET0510"],"techniques":["T1027.017"]},{"id":"AN1409","stix_id":"x-mitre-analytic--fe1cff12-9772-4ba9-92bc-c26eae79da24","name":"Analytic 1409","description":"Detects SVGs downloaded via browser that invoke AppleScript, osascript, or JavaScriptCore processes, followed by network egress or file drop to LaunchAgents or ~/Library.","url":"https://attack.mitre.org/detectionstrategies/DET0510#AN1409","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"subsystem: com.apple.WebKit or com.apple.WebKit.Networking","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ScriptEngines","description":"Scriptable binaries such as osascript, jsc, JavaScriptCore – may vary by OS version"},{"field":"UserContext","description":"Restrict to non-system users or only specific login sessions"},{"field":"EmbeddedContentIndicators","description":"SVGs embedded inside PDFs or HTML with script-based triggers"}],"live":true,"detection_strategies":["DET0510"],"techniques":["T1027.017"]}],"live":true,"version":"1.0","techniques":["T1027.017"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}