{"id":"T1080","name":"Taint Shared Content","url":"https://attack.mitre.org/techniques/T1080","tactics":["lateral-movement"],"platforms":["Windows","SaaS","Linux","macOS","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0471","stix_id":"x-mitre-detection-strategy--cdfe6166-43e9-434a-a961-139edd58ca0c","name":"Detection of Tainted Content Written to Shared Storage","url":"https://attack.mitre.org/detectionstrategies/DET0471","analytics":[{"id":"AN1298","stix_id":"x-mitre-analytic--a0554596-7100-4f8b-a4dd-165f528fe6a1","name":"Analytic 1298","description":"Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0471#AN1298","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=5145","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"SharedPathPrefix","description":"Defines monitored shared directories (e.g., \\\\server\\HR\\)."},{"field":"ExecutableExtensions","description":"Monitored file types dropped in shared paths (e.g., .lnk, .exe, .vbs)."}],"live":true,"detection_strategies":["DET0471"],"techniques":["T1080"]},{"id":"AN1299","stix_id":"x-mitre-analytic--7518f788-43dd-440a-955c-870cdb7dea26","name":"Analytic 1299","description":"Detects script or binary modification within shared NFS/SMB directories followed by process execution from those paths.","url":"https://attack.mitre.org/detectionstrategies/DET0471#AN1299","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"smb_files.log","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MountPath","description":"Mount path of monitored shared volumes (e.g., /mnt/shared)."},{"field":"FilenamePattern","description":"Pattern matching of abnormal or disguised filenames."}],"live":true,"detection_strategies":["DET0471"],"techniques":["T1080"]},{"id":"AN1300","stix_id":"x-mitre-analytic--3f36a861-3be2-4f6d-bfad-f044cdc01b15","name":"Analytic 1300","description":"Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app).","url":"https://attack.mitre.org/detectionstrategies/DET0471#AN1300","platforms":["macOS"],"log_source_references":[{"name":"fs:fsevents","channel":"Directory events (kFSEventStreamEventFlagItemCreated)","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsevents"},{"name":"macos:unifiedlog","channel":"file writes","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"FileExtensionDeception","description":"Monitors use of hidden extensions or double extensions."},{"field":"TargetSharedFolder","description":"Defines sensitive shared folders (e.g., /Users/Shared/HR)."}],"live":true,"detection_strategies":["DET0471"],"techniques":["T1080"]},{"id":"AN1301","stix_id":"x-mitre-analytic--49e91c60-9b73-4a0a-9510-f94152a8ba5e","name":"Analytic 1301","description":"Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions.","url":"https://attack.mitre.org/detectionstrategies/DET0471#AN1301","platforms":["SaaS"],"log_source_references":[{"name":"gcp:workspaceaudit","channel":"drive.activity logs","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"gcp-workspaceaudit"},{"name":"m365:unified","channel":"FileUploaded, FileAccessed","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"UserUploadRateThreshold","description":"Abnormal upload patterns into shared drives."},{"field":"MaliciousFileIndicator","description":"File hash or known-bad filename pattern matching."}],"live":true,"detection_strategies":["DET0471"],"techniques":["T1080"]},{"id":"AN1302","stix_id":"x-mitre-analytic--bc143cf2-d6fb-4ea4-98a5-a2db81fc3f84","name":"Analytic 1302","description":"Detects embedded macros or scripts added to shared documents or use of external references to execute code.","url":"https://attack.mitre.org/detectionstrategies/DET0471#AN1302","platforms":["Office Suite"],"log_source_references":[{"name":"m365:defender","channel":"OfficeTelemetry or DLP","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"m365-defender"}],"mutable_elements":[{"field":"MacroExecutionPolicy","description":"Controls macro execution based on user or group policy."},{"field":"SuspiciousKeywordMatch","description":"Regex match on suspicious VBA function names or calls."}],"live":true,"detection_strategies":["DET0471"],"techniques":["T1080"]}],"live":true,"version":"1.0","techniques":["T1080"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}