{"id":"T1204.005","name":"Malicious Library","url":"https://attack.mitre.org/techniques/T1204/005","tactics":["execution"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0252","stix_id":"x-mitre-detection-strategy--09caebdc-2ce4-4698-a40c-d91cb65f9720","name":"User-Initiated Malicious Library Installation via Package Manager (T1204.005)","url":"https://attack.mitre.org/detectionstrategies/DET0252","analytics":[{"id":"AN0698","stix_id":"x-mitre-analytic--223a39c8-d194-456e-be99-2db9e97ab7da","name":"Analytic 0698","description":"User-initiated installation of Python (pip), NodeJS (npm), or other language libraries, followed by unexpected network connections, credential access, or startup file modifications. Defender sees `pip install` or `npm install` commands run by a non-root user, followed shortly by new `.py`, `.sh`, or `.js` files in hidden directories, or interpreter-based execution during boot/login.","url":"https://attack.mitre.org/detectionstrategies/DET0252#AN0698","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of pip, npm, gem, or similar package managers","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"New .py/.js/.sh files written to ~/.local/, ~/.cache/, or /tmp/ within 5 min of package install","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-path"},{"name":"NSM:Flow","channel":"http::request: Network connection to package registry or C2 from interpreter shortly after install","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PackageManagerList","description":"Monitored package managers (e.g., pip, npm, gem, poetry, conda)"},{"field":"InstallWritePaths","description":"Directories to watch for post-install execution artifacts (e.g., ~/.local/, /usr/lib/python3.8/site-packages/)"},{"field":"UserContextScope","description":"Filter to focus on non-system accounts (e.g., interactive shell users)"},{"field":"TimeWindow","description":"Correlate install command to subsequent network/file activity (default: 5 min)"}],"live":true,"detection_strategies":["DET0252"],"techniques":["T1204.005"]},{"id":"AN0699","stix_id":"x-mitre-analytic--05985fc7-44cf-4b28-8d4f-14c1662bc5ea","name":"Analytic 0699","description":"Execution of `pip.exe`, `npm.cmd`, or MSI installers within user context, followed by script interpreter startup (e.g., python.exe) or PowerShell with unusual child processes or file writes in `%APPDATA%`, `%TEMP%`, or `%LOCALAPPDATA%`. Defender correlates command-line install tools with Sysmon and Event Logs to trace downstream behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0252#AN0699","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedParentProcesses","description":"Filter expected automation tools (e.g., enterprise installers, known IDEs)"},{"field":"InstallPathsToWatch","description":"Suspicious post-install write paths (e.g., %APPDATA%, %TEMP%)"},{"field":"ExecutableEntropyThreshold","description":"Used for evaluating if dropped files are packed/obfuscated"}],"live":true,"detection_strategies":["DET0252"],"techniques":["T1204.005"]},{"id":"AN0700","stix_id":"x-mitre-analytic--98f18ad5-0def-4ac3-8822-7538f0a8d64d","name":"Analytic 0700","description":"Execution of Homebrew, pip3, npm, or manually downloaded PKGs from Terminal or shell, followed by the creation of startup agents, interpreter spawns, or outbound connections to unfamiliar domains. Defender links Terminal commands to plist creation, unsigned binary launches, and `python3` or `node` processes connecting to remote endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0252#AN0700","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Command line invocation of pip3, brew install, npm install from interactive Terminal","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of new LaunchAgent or LoginItem plist files in ~/Library/LaunchAgents/","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Outbound HTTP/S initiated by newly installed interpreter process","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"StartupAgentPaths","description":"Filter user persistence plist directories like ~/Library/LaunchAgents"},{"field":"UnsignedBinaryAlerting","description":"Enable alerting for new binaries lacking Apple or organization signature"},{"field":"InstallToNetWindow","description":"Correlate install action to interpreter-based network behavior"}],"live":true,"detection_strategies":["DET0252"],"techniques":["T1204.005"]}],"live":true,"version":"1.0","techniques":["T1204.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}