{"id":"T1204","name":"User Execution","url":"https://attack.mitre.org/techniques/T1204","tactics":["execution"],"platforms":["Linux","Windows","macOS","IaaS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0478","stix_id":"x-mitre-detection-strategy--70c9f174-2e96-4086-b59c-d2358e434f8e","name":"User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)","url":"https://attack.mitre.org/detectionstrategies/DET0478","analytics":[{"id":"AN1314","stix_id":"x-mitre-analytic--dcd6253b-a986-4c8a-bd89-46389007ea83","name":"Analytic 1314","description":"Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0478#AN1314","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Application","channel":"EventCode=1000","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window (e.g., 15 minutes) from document open to child/egress."},{"field":"HighRiskParents","description":"Apps that should rarely spawn OS utilities (winword.exe, excel.exe, powerpnt.exe, acrord32.exe, chrome/msedge/firefox, 7zFM.exe, winrar.exe, explorer.exe)."},{"field":"HighRiskChildren","description":"LOLBIN list: powershell.exe, cmd.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, msiexec.exe, curl.exe, bitsadmin.exe, pcalua.exe, expand.exe, tar.exe."},{"field":"UserPaths","description":"Writable paths to watch: %USERPROFILE%\\Downloads, %TEMP%, %APPDATA%\\*, OneDrive/Teams cache, Office startup folders."},{"field":"EgressAllowList","description":"Corporate update/CDN domains and proxy egress CIDRs to suppress benign updater traffic."}],"live":true,"detection_strategies":["DET0478"],"techniques":["T1204"]},{"id":"AN1315","stix_id":"x-mitre-analytic--a6e7697d-f0b8-4fcc-b32a-fec5b28cd8f7","name":"Analytic 1315","description":"Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s) from the child lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0478#AN1315","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"opened document|clicked link|segfault|abnormal termination|sandbox","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"creat","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"rename,chmod","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"new outbound connection from browser/office lineage","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"5–20 minute correlation window."},{"field":"UserPaths","description":"$HOME/Downloads, /tmp, ~/.cache, ~/.config/autostart, ~/.local/share."},{"field":"HighRiskChildren","description":"bash, sh, zsh, python*, perl, node, curl, wget, xdg-open, kde-open, gio open, unzip/tar extraction leading to exec."},{"field":"PkgUpdaters","description":"Allow-list snap/flatpak/packagekit/apt workers to reduce false positives."}],"live":true,"detection_strategies":["DET0478"],"techniques":["T1204"]},{"id":"AN1316","stix_id":"x-mitre-analytic--66107cd1-c123-4ad5-bb0b-62d8a9a451a6","name":"Analytic 1316","description":"Cause→effect chain: (1) unified logs show application open/click or crash for Safari/Chrome/Office/Preview/archiver, (2) file write/extraction into ~/Downloads, /private/var/folders/* or ~/Library, (3) parent app spawns osascript/bash/zsh/curl/python or opens a quarantined app with Gatekeeper prompts, (4) network egress from child.","url":"https://attack.mitre.org/detectionstrategies/DET0478#AN1316","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"opened document|clicked link|EXC_BAD_ACCESS|abort|LSQuarantine","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"fs:fileevents","channel":"create/write/rename in user-writable paths","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fileevents"},{"name":"macos:osquery","channel":"exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:Flow","channel":"new outbound connection from exploited lineage","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"10–30 minute correlation window."},{"field":"HighRiskChildren","description":"osascript, bash, zsh, curl, python, open -a Terminal, installer, tccutil misuse."},{"field":"QuarantineSignals","description":"Flag new apps lacking com.apple.quarantine or with quarantine='0081' (downloaded then auto-opened)."}],"live":true,"detection_strategies":["DET0478"],"techniques":["T1204"]},{"id":"AN1317","stix_id":"x-mitre-analytic--3a6fdd1a-59c6-4f46-a761-0de502229da0","name":"Analytic 1317","description":"Cause→effect chain in CI/dev desktops: (1) user triggers container run/pull after opening a doc/link/script, (2) newly created image/container uses unexpected external registry or entrypoint, (3) container starts and immediately egresses to suspicious destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0478#AN1317","platforms":["Containers"],"log_source_references":[{"name":"docker:events","channel":"created,started: new container from untrusted registry or unexpected entrypoint","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"docker-events"},{"name":"docker:events","channel":"start","data_component":"DC0077","data_component_name":"Container Start","log_source_slug":"docker-events"},{"name":"NSM:Flow","channel":"container egress to unknown IPs/domains","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TrustedRegistries","description":"Approved registries/namespaces."},{"field":"AllowedEntrypoints","description":"Expected CMD/ENTRYPOINT for known images."},{"field":"TimeWindow","description":"Correlate user action → docker/podman run within 10 minutes."}],"live":true,"detection_strategies":["DET0478"],"techniques":["T1204"]},{"id":"AN1318","stix_id":"x-mitre-analytic--e707cd33-8e20-4b1d-ad3f-fd3a3233fcdd","name":"Analytic 1318","description":"Cause→effect chain in cloud consoles: (1) user clicks link then invokes instance/image creation via API, (2) instance/image originates from external AMI or unknown image, (3) instance immediately egresses or retrieves payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0478#AN1318","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RunInstances,CreateImage","data_component":"DC0076","data_component_name":"Instance Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"StartInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"gcp:vpcflow","channel":"first 5m egress to unknown ASNs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"gcp-vpcflow"}],"mutable_elements":[{"field":"ApprovedImages","description":"AMI/image allow-list with owners."},{"field":"UserContext","description":"High-risk identities (federated, external IdP)."},{"field":"TimeWindow","description":"5–30 minutes from console/API action to network egress."}],"live":true,"detection_strategies":["DET0478"],"techniques":["T1204"]}],"live":true,"version":"1.0","techniques":["T1204"]}],"sigma_rules":[{"id":"1412aa78-a24c-4abd-83df-767dfb2c5bbe","title":"Potentially Suspicious WebDAV LNK Execution","author":"Micah Babinski","status":"test","level":"medium","date":"2023-08-21","modified":null,"description":"Detects possible execution via LNK file accessed on a WebDAV server.","references":["https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html","https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.001","attack.t1204"],"path":"rules/windows/process_creation/proc_creation_win_webdav_lnk_execution.yml","techniques":["T1059.001","T1204"],"cves":[]},{"id":"234dc5df-40b5-49d1-bf53-0d44ce778eca","title":"Payload Decoded and Decrypted via Built-in Utilities","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-17","modified":null,"description":"Detects when a built-in utility is used to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into executing malicious code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d42c3d772e04f1e8d0eb60f5233bc79def1ea73105a2d8822f44164f77ef823"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.stealth","attack.t1059","attack.t1204","attack.execution","attack.t1140","attack.s0482","attack.s0402"],"path":"rules/macos/process_creation/proc_creation_macos_payload_decoded_and_decrypted.yml","techniques":["T1059","T1204","T1140"],"cves":[]},{"id":"24de4f3b-804c-4165-b442-5a06a2302c7e","title":"Arbitrary Shell Command Execution Via Settingcontent-Ms","author":"Sreeman","status":"test","level":"medium","date":"2020-03-13","modified":"2022-04-14","description":"The .SettingContent-ms file type was introduced in Windows 10 and allows a user to create \"shortcuts\" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.","references":["https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1204","attack.t1566.001","attack.execution","attack.initial-access"],"path":"rules/windows/process_creation/proc_creation_win_susp_arbitrary_shell_execution_via_settingcontent.yml","techniques":["T1204","T1566.001"],"cves":[]},{"id":"5325945e-f1f0-406e-97b8-65104d393fff","title":"Potential Snatch Ransomware Activity","author":"Florian Roth (Nextron Systems)","status":"stable","level":"high","date":"2020-08-26","modified":"2025-10-19","description":"Detects specific process characteristics of Snatch ransomware word document droppers","references":["https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/Snatch/proc_creation_win_malware_snatch_ransomware.yml","techniques":["T1204"],"cves":[]},{"id":"6c0ce3b6-85e2-49d4-9c3f-6e008ce9796e","title":"Suspicious Deno File Written from Remote Source","author":"Josh Nickels, Michael Taggart","status":"experimental","level":"low","date":"2025-05-22","modified":null,"description":"Detects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL.\nThis behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.\n","references":["https://taggart-tech.com/evildeno/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1204","attack.t1059.007","attack.command-and-control","attack.t1105"],"path":"rules/windows/file/file_event/file_event_win_creation_deno.yml","techniques":["T1204","T1059.007","T1105"],"cves":[]},{"id":"6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4","title":"Suspicious Execution via macOS Script Editor","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":"2022-12-28","description":"Detects when the macOS Script Editor utility spawns an unusual child process.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-7f541fbc4a4a28a92970e8bf53effea5bd934604429112c920affb457f5b2685","https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1566","attack.t1566.002","attack.initial-access","attack.t1059","attack.t1059.002","attack.t1204","attack.t1204.001","attack.execution","attack.persistence","attack.t1553"],"path":"rules/macos/process_creation/proc_creation_macos_susp_execution_macos_script_editor.yml","techniques":["T1566","T1566.002","T1059","T1059.002","T1204","T1204.001","T1553"],"cves":[]},{"id":"965fff6c-1d7e-4e25-91fd-cdccd75f7d2c","title":"DarkSide Ransomware Pattern","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-05-14","modified":null,"description":"Detects DarkSide Ransomware and helpers","references":["https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html","https://app.any.run/tasks/8b9a571b-bcc1-4783-ba32-df4ba623b9c0/","https://www.joesandbox.com/analysis/411752/0/html#7048BB9A06B8F2DD9D24C77F389D7B2B58D2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/DarkSide/proc_creation_win_malware_darkside_ransomware.yml","techniques":["T1204"],"cves":[]},{"id":"b447f7de-1e53-4cbf-bfb4-f1f6d0b04e4e","title":"Suspicious Binaries and Scripts in Public Folder","author":"The DFIR Report","status":"experimental","level":"high","date":"2025-01-23","modified":null,"description":"Detects the creation of a file with a suspicious extension in the public folder, which could indicate potential malicious activity.","references":["https://intel.thedfirreport.com/events/view/30032","https://intel.thedfirreport.com/eventReports/view/70","https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1204"],"path":"rules/windows/file/file_event/file_event_win_susp_public_folder_extension.yml","techniques":["T1204"],"cves":[]},{"id":"ba6b9e43-1d45-4d3c-a504-1043a64c8469","title":"PrinterNightmare Mimikatz Driver Name","author":"Markus Neis, @markus_neis, Florian Roth","status":"test","level":"critical","date":"2021-07-04","modified":"2023-06-12","description":"Detects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527","references":["https://github.com/gentilkiwi/mimikatz/commit/c21276072b3f2a47a21e215a46962a17d54b3760","https://www.lexjansen.com/sesug/1993/SESUG93035.pdf","https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rprn/4464eaf0-f34f-40d5-b970-736437a21913","https://nvd.nist.gov/vuln/detail/cve-2021-1675","https://nvd.nist.gov/vuln/detail/cve-2021-34527"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.execution","attack.t1204","cve.2021-1675","cve.2021-34527","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-1675/registry_event_cve_2021_1675_mimikatz_printernightmare_drivers.yml","techniques":["T1204"],"cves":["CVE-2021-1675","CVE-2021-34527"]},{"id":"fa0c05b6-8ad3-468d-8231-c1cbccb64fba","title":"Antivirus - Hacktool Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"high","date":"2021-08-16","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/","https://www.nextron-systems.com/?s=antivirus"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1204"],"path":"rules/category/antivirus/av_hacktool.yml","techniques":["T1204"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-24993","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-38831","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}