{"id":"T1659","name":"Content Injection","url":"https://attack.mitre.org/techniques/T1659","tactics":["initial-access","command-and-control"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0349","stix_id":"x-mitre-detection-strategy--7a084a47-c4ea-4996-8d23-ffe0b19206fb","name":"Detection Strategy for Content Injection","url":"https://attack.mitre.org/detectionstrategies/DET0349","analytics":[{"id":"AN0992","stix_id":"x-mitre-analytic--8384d942-2f83-4968-9959-fd2f55afb311","name":"Analytic 0992","description":"Detect suspicious file creations and process executions triggered by browser activity (e.g., injected payloads written to %AppData% or Temp directories, then executed). Correlate network anomalies with subsequent local process creation or script execution.","url":"https://attack.mitre.org/detectionstrategies/DET0349#AN0992","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Unexpected script or binary content returned in HTTP response body","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredExtensions","description":"File extensions to flag (exe, dll, js, vbs, sh, etc.)."},{"field":"SuspiciousParentProcesses","description":"Browser processes (chrome.exe, firefox.exe, edge.exe, etc.) monitored as possible parents for malicious activity."},{"field":"RedirectList","description":"List of suspicious domains or URLs used for malicious redirects."}],"live":true,"detection_strategies":["DET0349"],"techniques":["T1659"]},{"id":"AN0993","stix_id":"x-mitre-analytic--5e8af32c-5246-43e1-a7d9-c4d263c7b135","name":"Analytic 0993","description":"Detect curl/wget commands saving executable/script payloads to /tmp or /var/tmp followed by execution. Monitor packet captures or IDS/IPS alerts for injected responses or mismatched content types.","url":"https://attack.mitre.org/detectionstrategies/DET0349#AN0993","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of curl or wget writing files to /tmp/* followed by chmod or execution","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"WinEventLog:Sysmon","channel":"File creation of suspicious scripts/binaries in temporary directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Injected content responses with unexpected script/malware signatures","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TempDirectories","description":"Directories such as /tmp and /var/tmp where injected files are often written."}],"live":true,"detection_strategies":["DET0349"],"techniques":["T1659"]},{"id":"AN0994","stix_id":"x-mitre-analytic--ba6a9282-30e0-491c-90a7-35bf4ad25ba3","name":"Analytic 0994","description":"Monitor unified logs for processes spawned from Safari or other browsers that immediately load scripts or executables. Detect file drops in ~/Library/Caches or ~/Downloads that execute shortly after being written.","url":"https://attack.mitre.org/detectionstrategies/DET0349#AN0994","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Child processes of Safari, Chrome, or Firefox executing scripting interpreters","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"File creation of unsigned binaries/scripts in user cache or download directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Content injection observed in HTTPS responses with mismatched certificates or altered payloads","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredDirectories","description":"macOS-specific directories where malicious payloads may be written."}],"live":true,"detection_strategies":["DET0349"],"techniques":["T1659"]}],"live":true,"version":"1.0","techniques":["T1659"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}