{"id":"T1497.002","name":"User Activity Based Checks","url":"https://attack.mitre.org/techniques/T1497/002","tactics":["stealth","discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0420","stix_id":"x-mitre-detection-strategy--5463d676-c300-4ab8-9980-d3ed37ac4723","name":"Detect User Activity Based Sandbox Evasion via Input & Artifact Probing","url":"https://attack.mitre.org/detectionstrategies/DET0420","analytics":[{"id":"AN1182","stix_id":"x-mitre-analytic--5bd6658f-4391-4d77-bed8-9b141b0fa3ae","name":"Analytic 1182","description":"Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events.","url":"https://attack.mitre.org/detectionstrategies/DET0420#AN1182","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4800, 4801","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TimeWindow","description":"Window between user unlock and access to user history"},{"field":"UserContext","description":"Focus on non-system accounts doing user activity probing"}],"live":true,"detection_strategies":["DET0420"],"techniques":["T1497.002"]},{"id":"AN1183","stix_id":"x-mitre-analytic--21773356-1c94-4edc-b368-008c86a5929e","name":"Analytic 1183","description":"Access to shell history or GUI input state (xdotool, xinput) for presence validation prior to payload execution.","url":"https://attack.mitre.org/detectionstrategies/DET0420#AN1183","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"Reads of ~/.bash_history, ~/.mozilla, or access to /dev/input","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"Execution of xev, xdotool, or input activity emulators","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ArtifactCountThreshold","description":"Number of distinct user files accessed before trigger"},{"field":"KnownToolSignatures","description":"Suppress expected automation tools"}],"live":true,"detection_strategies":["DET0420"],"techniques":["T1497.002"]},{"id":"AN1184","stix_id":"x-mitre-analytic--e3a0ea8d-0018-4603-912a-4d40d0f75390","name":"Analytic 1184","description":"API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState).","url":"https://attack.mitre.org/detectionstrategies/DET0420#AN1184","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of input detection APIs (e.g., CGEventSourceKeyState)","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Access to ~/Library/Safari/Bookmarks.plist or recent files","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TimeWindow","description":"Temporal correlation between login and file access"},{"field":"UserContext","description":"Exclude expected UI activity from login agents"}],"live":true,"detection_strategies":["DET0420"],"techniques":["T1497.002"]}],"live":true,"version":"1.0","techniques":["T1497.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}