{"id":"T1566.001","name":"Spearphishing Attachment","url":"https://attack.mitre.org/techniques/T1566/001","tactics":["initial-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0236","stix_id":"x-mitre-detection-strategy--8d904004-e492-4f76-9f84-be75fc61e5c5","name":"Detection Strategy for Spearphishing Attachment across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0236","analytics":[{"id":"AN0655","stix_id":"x-mitre-analytic--db6995d9-68ab-4638-a430-c0a8d2daf306","name":"Analytic 0655","description":"Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0236#AN0655","platforms":["Windows"],"log_source_references":[{"name":"m365:unified","channel":"Send/Receive: Inbound emails with attachments from suspicious or spoofed senders","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AttachmentExtensions","description":"List of high-risk extensions to monitor (e.g., .exe, .js, .vbs, .docm, .xlsm)."},{"field":"SuspiciousParentChildPairs","description":"Process lineage patterns considered malicious (e.g., winword.exe → powershell.exe)."},{"field":"TimeWindow","description":"Correlation window between email receipt, file creation, and process execution."}],"live":true,"detection_strategies":["DET0236"],"techniques":["T1566.001"]},{"id":"AN0656","stix_id":"x-mitre-analytic--02309791-384c-4ca9-b25c-6a6bc754795f","name":"Analytic 0656","description":"Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0236#AN0656","platforms":["Linux"],"log_source_references":[{"name":"Application:Mail","channel":"Inbound email attachments logged from MTAs with suspicious metadata","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"},{"name":"auditd:SYSCALL","channel":"execve: Execution of files saved in mail or download directories","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound traffic from suspicious new processes post-attachment execution","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AttachmentStoragePaths","description":"Monitored directories for email attachments (e.g., /var/mail, ~/Maildir, ~/Downloads)."},{"field":"ScriptInterpreters","description":"List of interpreters to monitor when spawned by mail clients (e.g., bash, python, perl)."}],"live":true,"detection_strategies":["DET0236"],"techniques":["T1566.001"]},{"id":"AN0657","stix_id":"x-mitre-analytic--7a6192b4-997a-4526-bb3d-76664bc31274","name":"Analytic 0657","description":"Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.","url":"https://attack.mitre.org/detectionstrategies/DET0236#AN0657","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Inbound messages with attachments from suspicious domains","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of Terminal, osascript, or other interpreters originating from Mail or Preview","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Attachment files written to ~/Downloads or temporary folders","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExecutionDelayThreshold","description":"Time delay between attachment download and execution considered suspicious."},{"field":"SuspiciousParentApps","description":"Parent processes expected to rarely spawn child processes (e.g., Mail.app, Preview.app)."}],"live":true,"detection_strategies":["DET0236"],"techniques":["T1566.001"]}],"live":true,"version":"1.0","techniques":["T1566.001"]}],"sigma_rules":[{"id":"023394c4-29d5-46ab-92b8-6a534c6f447b","title":"Suspicious HWP Sub Processes","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation","references":["https://www.securitynewspaper.com/2016/11/23/technical-teardown-exploit-malware-hwp-files/","https://www.hybrid-analysis.com/search?query=context:74940dcc5b38f9f9b1a0fea760d344735d7d91b610e6d5bd34533dd0153402c5&from_sample=5db135000388385a7644131f&block_redirect=1","https://twitter.com/cyberwar_15/status/1187287262054076416","https://blog.alyac.co.kr/1901","https://en.wikipedia.org/wiki/Hangul_(word_processor)"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566.001","attack.execution","attack.t1203","attack.t1059.003","attack.g0032"],"path":"rules/windows/process_creation/proc_creation_win_hwp_exploits.yml","techniques":["T1566.001","T1203","T1059.003"],"cves":[]},{"id":"0248a7bc-8a9a-4cd8-a57e-3ae8e073a073","title":"ISO Image Mounted","author":"Syed Hasan (@syedhasan009)","status":"test","level":"medium","date":"2021-05-29","modified":"2023-11-09","description":"Detects the mount of an ISO image on an endpoint","references":["https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/malicious-spam-campaign-uses-iso-image-files-to-deliver-lokibot-and-nanocore","https://www.proofpoint.com/us/blog/threat-insight/threat-actor-profile-ta2719-uses-colorful-lures-deliver-rats-local-languages","https://twitter.com/MsftSecIntel/status/1257324139515269121","https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1553.005/T1553.005.md#atomic-test-1---mount-iso-image"],"logsource":{"product":"windows","service":"security"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/builtin/security/win_security_iso_mount.yml","techniques":["T1566.001"],"cves":[]},{"id":"0e29e3a7-1ad8-40aa-b691-9f82ecd33d66","title":"Office Macro File Download","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-01-23","modified":"2025-10-29","description":"Detects the creation of a new office macro files on the system via an application (browser, mail client).\nThis can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md","https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_office_macro_files_downloaded.yml","techniques":["T1566.001"],"cves":[]},{"id":"1cdd9a09-06c9-4769-99ff-626e2b3991b8","title":"Suspicious Double Extension File Execution","author":"Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems)","status":"stable","level":"high","date":"2019-06-26","modified":"2025-05-30","description":"Detects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns","references":["https://blu3-team.blogspot.com/2019/06/misleading-extensions-xlsexe-docexe.html","https://twitter.com/blackorbird/status/1140519090961825792","https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_double_extension.yml","techniques":["T1566.001"],"cves":[]},{"id":"24de4f3b-804c-4165-b442-5a06a2302c7e","title":"Arbitrary Shell Command Execution Via Settingcontent-Ms","author":"Sreeman","status":"test","level":"medium","date":"2020-03-13","modified":"2022-04-14","description":"The .SettingContent-ms file type was introduced in Windows 10 and allows a user to create \"shortcuts\" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.","references":["https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1204","attack.t1566.001","attack.execution","attack.initial-access"],"path":"rules/windows/process_creation/proc_creation_win_susp_arbitrary_shell_execution_via_settingcontent.yml","techniques":["T1204","T1566.001"],"cves":[]},{"id":"295a59c1-7b79-4b47-a930-df12c15fc9c2","title":"Windows Registry Trust Record Modification","author":"Antonlovesdnb, Trent Liffick (@tliffick)","status":"test","level":"medium","date":"2020-02-19","modified":"2023-06-21","description":"Alerts on trust record modification within the registry, indicating usage of macros","references":["https://outflank.nl/blog/2018/01/16/hunting-for-evil-detect-macros-being-executed/","http://az4n6.blogspot.com/2016/02/more-on-trust-records-macros-and.html","https://twitter.com/inversecos/status/1494174785621819397"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/registry/registry_event/registry_event_office_trust_record_modification.yml","techniques":["T1566.001"],"cves":[]},{"id":"2f9356ae-bf43-41b8-b858-4496d83b2acb","title":"ISO File Created Within Temp Folders","author":"@sam0x90","status":"test","level":"high","date":"2022-07-30","modified":null,"description":"Detects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.","references":["https://twitter.com/Sam0x90/status/1552011547974696960","https://securityaffairs.co/wordpress/133680/malware/dll-sideloading-spread-qakbot.html","https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1553.005/T1553.005.md#atomic-test-1---mount-iso-image"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_iso_file_mount.yml","techniques":["T1566.001"],"cves":[]},{"id":"3569aefd-e535-4391-8c18-24bd01a21eaf","title":"Suspicious Email Delivered In Microsoft 365","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-01-27","modified":null,"description":"Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.\nIt might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.\n","references":["https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about","https://research.splunk.com/cloud/605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2/","https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules/blob/e7250648cb16d4a497ae8737943bf010ea96d2e6/Defender%20For%20Cloud%20Apps/MaliciousEmailDeliveredInMailbox.md"],"logsource":{"product":"m365","service":"audit"},"tags":["attack.initial-access","attack.t1566.001","attack.t1566.002"],"path":"rules/cloud/m365/audit/microsoft365_suspicious_email_delivered.yml","techniques":["T1566.001","T1566.002"],"cves":[]},{"id":"4358e5a5-7542-4dcb-b9f3-87667371839b","title":"ISO or Image Mount Indicator in Recent Files","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-02-11","modified":null,"description":"Detects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks.\nThis can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.\n","references":["https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/","https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/malicious-spam-campaign-uses-iso-image-files-to-deliver-lokibot-and-nanocore","https://blog.emsisoft.com/en/32373/beware-new-wave-of-malware-spreads-via-iso-file-email-attachments/","https://insights.sei.cmu.edu/blog/the-dangers-of-vhd-and-vhdx-files/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_iso_file_recent.yml","techniques":["T1566.001"],"cves":[]},{"id":"52cad028-0ff0-4854-8f67-d25dfcbc78b4","title":"HTML Help HH.EXE Suspicious Child Process","author":"Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious child process of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"538c5851-8c03-4724-8ec4-623bc7aadaea","title":"HTML File Opened From Download Folder","author":"Joseph Kamau","status":"experimental","level":"low","date":"2025-12-05","modified":null,"description":"Detects web browser process opening an HTML file from a user's Downloads folder.\nThis behavior is could be associated with phishing attacks where threat actors send HTML attachments to users.\nWhen a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware.\nDuring investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.\n","references":["https://app.any.run/tasks/ae3c4ded-fd6a-43ed-8215-ba0ba574ad33","https://app.any.run/tasks/8901e2d5-0c5a-48ba-a8e9-10b5ed7e06f4"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1598.002","attack.t1566.001","attack.initial-access","attack.reconnaissance","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_open_html_file_from_download_folder.yml","techniques":["T1598.002","T1566.001"],"cves":[]},{"id":"571498c8-908e-40b4-910b-d2369159a3da","title":"Password Protected ZIP File Opened (Email Attachment)","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-05-09","modified":null,"description":"Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.","references":["https://twitter.com/sbousseaden/status/1523383197513379841"],"logsource":{"product":"windows","service":"security"},"tags":["attack.initial-access","attack.stealth","attack.t1027","attack.t1566.001"],"path":"rules/windows/builtin/security/win_security_susp_opened_encrypted_zip_outlook.yml","techniques":["T1027","T1566.001"],"cves":[]},{"id":"678eb5f4-8597-4be6-8be7-905e4234b53a","title":"Droppers Exploiting CVE-2017-11882","author":"Florian Roth (Nextron Systems)","status":"stable","level":"critical","date":"2017-11-23","modified":"2021-11-27","description":"Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe","references":["https://www.hybrid-analysis.com/sample/2a4ae284c76f868fc51d3bb65da8caa6efacb707f265b25c30f34250b76b7507?environmentId=100","https://www.linkedin.com/pulse/exploit-available-dangerous-ms-office-rce-vuln-called-thebenygreen-","https://github.com/embedi/CVE-2017-11882"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-11882","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-11882/proc_creation_win_exploit_cve_2017_11882.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-11882"]},{"id":"864403a1-36c9-40a2-a982-4c9a45f7d833","title":"Exploit for CVE-2017-0261","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-02-22","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262","references":["https://www.fireeye.com/blog/threat-research/2017/05/eps-processing-zero-days.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-0261","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-0261/proc_creation_win_exploit_cve_2017_0261.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-0261"]},{"id":"91174a41-dc8f-401b-be89-7bfc140612a0","title":"Office Macro File Creation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-01-23","modified":"2026-01-09","description":"Detects the creation of a new office macro files on the systems","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md","https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_office_macro_files_created.yml","techniques":["T1566.001"],"cves":[]},{"id":"932ac737-33ca-4afd-9869-0d48b391fcc9","title":"Ursnif Malware C2 URL Pattern","author":"Thomas Patzke","status":"stable","level":"critical","date":"2019-12-19","modified":"2021-08-09","description":"Detects Ursnif C2 traffic.","references":["https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566.001","attack.execution","attack.t1204.002","attack.command-and-control","attack.t1071.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/Ursnif/proxy_malware_ursnif_c2_url.yml","techniques":["T1566.001","T1204.002","T1071.001"],"cves":[]},{"id":"a018fdc3-46a3-44e5-9afb-2cd4af1d4b39","title":"Suspicious Execution From Outlook Temporary Folder","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-01","modified":"2022-10-09","description":"Detects a suspicious program execution in Outlook temp folder","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_office_outlook_execution_from_temp.yml","techniques":["T1566.001"],"cves":[]},{"id":"b1c50487-1967-4315-a026-6491686d860e","title":"Office Macro File Creation From Suspicious Process","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-01-23","modified":"2023-02-22","description":"Detects the creation of a office macro file from a a suspicious process","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md","https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_office_macro_files_from_susp_process.yml","techniques":["T1566.001"],"cves":[]},{"id":"bf241472-f014-4f01-a869-96f99330ca8c","title":"Disk Image Mounting Via Hdiutil - MacOS","author":"Omar Khaled (@beacon_exe)","status":"test","level":"medium","date":"2024-08-10","modified":null,"description":"Detects the execution of the hdiutil utility in order to mount disk images.","references":["https://www.loobins.io/binaries/hdiutil/","https://www.sentinelone.com/blog/from-the-front-linesunsigned-macos-orat-malware-gambles-for-the-win/","https://ss64.com/mac/hdiutil.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.collection","attack.t1566.001","attack.t1560.001"],"path":"rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml","techniques":["T1566.001","T1560.001"],"cves":[]},{"id":"c27515df-97a9-4162-8a60-dc0eeb51b775","title":"Suspicious Microsoft OneNote Child Process","author":"Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea)","status":"test","level":"high","date":"2022-10-21","modified":"2023-02-10","description":"Detects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-e34e43eb5666427602ddf488b2bf3b545bd9aae81af3e6f6c7949f9652abdf18","https://micahbabinski.medium.com/detecting-onenote-one-malware-delivery-407e9321ecf0"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1566","attack.t1566.001","attack.initial-access"],"path":"rules/windows/process_creation/proc_creation_win_office_onenote_susp_child_processes.yml","techniques":["T1566","T1566.001"],"cves":[]},{"id":"dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c","title":"Potential Initial Access via DLL Search Order Hijacking","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":null,"description":"Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d46dd4ac6866b4337ec126be8cee0e115467b3e8703794ba6f6df6432c806bc","https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1566","attack.t1566.001","attack.initial-access","attack.t1574","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_initial_access_dll_search_order_hijacking.yml","techniques":["T1566","T1566.001","T1574","T1574.001"],"cves":[]},{"id":"e8a95b5e-c891-46e2-b33a-93937d3abc31","title":"Suspicious HH.EXE Execution","author":"Maxim Pavlunin","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious execution of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_susp_execution.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"fabb0e80-030c-4e3e-a104-d09676991ac3","title":"Suspicious File Created in Outlook Temporary Directory","author":"Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-07-22","modified":null,"description":"Detects the creation of files with suspicious file extensions in the temporary directory that Outlook uses when opening attachments.\nThis can be used to detect spear-phishing campaigns that use suspicious files as attachments, which may contain malicious code.\n","references":["https://vipre.com/blog/svg-phishing-attacks-the-new-trick-in-the-cybercriminals-playbook/","https://thecyberexpress.com/rogue-rdp-files-used-in-ukraine-cyberattacks/","https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1566.001"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_susp_file_creation_in_temp_dir.yml","techniques":["T1566.001"],"cves":[]},{"id":"fdd84c68-a1f6-47c9-9477-920584f94905","title":"Exploit for CVE-2017-8759","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2017-09-15","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759","references":["https://www.hybrid-analysis.com/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100","https://www.reverse.it/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-8759","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-8759/proc_creation_win_exploit_cve_2017_8759.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-8759"]}],"kev_cves":[{"cveID":"CVE-2025-33053","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-0411","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-2868","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-41033","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2017-11292","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2013-0640","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2017-11882","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}