{"id":"T1684","name":"Social Engineering","url":"https://attack.mitre.org/techniques/T1684","tactics":["stealth"],"platforms":["Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0899","stix_id":"x-mitre-detection-strategy--48923678-0fb6-4d14-986b-2f6adeb8c421","name":"Detect Social Engineering","url":"https://attack.mitre.org/detectionstrategies/DET0899","analytics":[{"id":"AN2037","stix_id":"x-mitre-analytic--54bb8256-cbe8-4088-9cff-b03711bd7841","name":"Analytic 2037","description":"Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.","url":"https://attack.mitre.org/detectionstrategies/DET0899#AN2037","platforms":["Linux"],"log_source_references":[{"name":"NSM:Connections","channel":"Outbound connection after script or installer launch","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-connections"},{"name":"auditd:EXECVE","channel":"execve of curl,wget,bash,sh,python with piped or remote content","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:PATH","channel":"odification of ~/.ssh/authorized_keys or credential files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"RemoteScriptExecutionPatterns","description":"Organization-specific admin automation patterns to exclude"},{"field":"TicketToExecutionWindow","description":"Time from help desk/chat event to command execution"}],"live":true,"detection_strategies":["DET0899"],"techniques":["T1684"]},{"id":"AN2035","stix_id":"x-mitre-analytic--983e1849-6af7-491e-9605-46b9bf54bbd1","name":"Analytic 2035","description":"Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0899#AN2035","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"EmailToExecutionWindow","description":"Time between message delivery and process launch"},{"field":"OfficeChildProcessAllowlist","description":"Approved Office child process patterns"},{"field":"NewLogonWindow","description":"Time after credential prompt to monitor new sessions"}],"live":true,"detection_strategies":["DET0899"],"techniques":["T1684"]},{"id":"AN2034","stix_id":"x-mitre-analytic--e817eb45-0830-476d-9fd7-8e8acb14af8a","name":"Analytic 2034","description":"Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.","url":"https://attack.mitre.org/detectionstrategies/DET0899#AN2034","platforms":["SaaS"],"log_source_references":[{"name":"saas:okta","channel":"user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-okta"},{"name":"saas:slack","channel":"xternal DM or workspace invite preceding credential or approval actions","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-slack"},{"name":"saas:zoom","channel":"Unexpected contact interaction preceding follow-on admin requests","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-zoom"}],"mutable_elements":[{"field":"RequesterNoveltyDays","description":"How long since requestor last interacted with user"},{"field":"GeoVelocityThreshold","description":"Distance/time anomaly for follow-on login"},{"field":"AfterHoursDefinition","description":"Organization-specific off-hours period"}],"live":true,"detection_strategies":["DET0899"],"techniques":["T1684"]},{"id":"AN2033","stix_id":"x-mitre-analytic--f238e0f3-7354-4304-9101-69cefd8446fc","name":"Analytic 2033","description":"Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.\n      ","url":"https://attack.mitre.org/detectionstrategies/DET0899#AN2033","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"MailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"m365:exchange","channel":"External sender message followed by user action involving links or attachments","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-exchange"},{"name":"m365:teams","channel":"External chat request or new tenant communication preceding approval activity","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-teams"}],"mutable_elements":[{"field":"ActionAfterMessageWindow","description":"Time window between inbound communication and sensitive action"},{"field":"TrustedDomainAllowlist","description":"Known legitimate vendors or partner domains"},{"field":"ApprovalAmountThreshold","description":"Monetary threshold for finance workflows"}],"live":true,"detection_strategies":["DET0899"],"techniques":["T1684"]},{"id":"AN2036","stix_id":"x-mitre-analytic--fc19b602-2811-418f-aa98-1b49f1355743","name":"Analytic 2036","description":"Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0899#AN2036","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of osascript, sh, bash, zsh, installer, open","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Connections","channel":"Outbound connection after script or installer launch","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-connections"},{"name":"macos:unifiedlog","channel":"Recent download opened or executed","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DownloadToExecutionWindow","description":"Time between download and launch"},{"field":"InstallerParentAllowlist","description":"Legitimate software deployment parents"}],"live":true,"detection_strategies":["DET0899"],"techniques":["T1684"]}],"live":true,"version":"1.0","techniques":["T1684"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}