{"id":"T1204.002","name":"Malicious File","url":"https://attack.mitre.org/techniques/T1204/002","tactics":["execution"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0294","stix_id":"x-mitre-detection-strategy--e2023eb5-d813-4a08-985e-e8c998672037","name":"User Execution – Malicious File via download/open → spawn chain (T1204.002)","url":"https://attack.mitre.org/detectionstrategies/DET0294","analytics":[{"id":"AN0819","stix_id":"x-mitre-analytic--328d639e-6b8d-400c-9cdd-3c255d343e47","name":"Analytic 0819","description":"User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.","url":"https://attack.mitre.org/detectionstrategies/DET0294#AN0819","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Seconds/minutes to correlate file write to child spawn (e.g., 0–5m)."},{"field":"SuspiciousExtensions","description":"Extensions and double-extension patterns to flag (exe,scr,lnk,pif,cpl,js,vbs,bat,cmd,ps1,hta,iso,lnk->cmd,docm,xlsm,pdf->exe, etc.)."},{"field":"UserPaths","description":"Paths considered user-controlled (Downloads, Temp, Desktop, profile AppData staging)."},{"field":"ParentApps","description":"List of user-facing apps that commonly open attachments for your org (reduce FPs or add weight)."},{"field":"SignerAllowList","description":"Trusted code signers/publishers to suppress benign admin tools."}],"live":true,"detection_strategies":["DET0294"],"techniques":["T1204.002"]},{"id":"AN0820","stix_id":"x-mitre-analytic--5becf65d-da9f-46e1-8edc-eea05c9dc6cb","name":"Analytic 0820","description":"User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.","url":"https://attack.mitre.org/detectionstrategies/DET0294#AN0820","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder}","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_CREATE: path under /Users/*/(Downloads|Desktop|Library/*/Containers|Library/Group Containers) AND extension in SuspiciousExtensions","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between file create and exec (e.g., ≤10m)."},{"field":"QuarantineRequired","description":"Require com.apple.quarantine attribute present on the file for higher fidelity."},{"field":"ParentApps","description":"Approved document viewers/editors to anchor lineage."}],"live":true,"detection_strategies":["DET0294"],"techniques":["T1204.002"]},{"id":"AN0821","stix_id":"x-mitre-analytic--e0b64d4e-79e0-47b8-a95c-414e2b69406d","name":"Analytic 0821","description":"User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.","url":"https://attack.mitre.org/detectionstrategies/DET0294#AN0821","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/create/rename: name in (/home/*/Downloads/*|/tmp/*|/run/user/*|/media/*) AND ext in SuspiciousExtensions","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window for audit events (e.g., ≤5m)."},{"field":"DesktopParentMap","description":"Map common desktop apps (libreoffice, evince, firefox, chromium) for lineage anchoring."}],"live":true,"detection_strategies":["DET0294"],"techniques":["T1204.002"]}],"live":true,"version":"1.0","techniques":["T1204.002"]}],"sigma_rules":[{"id":"00d0b5ab-1f55-4120-8e83-487c0a7baf19","title":"Download From Suspicious TLD - Blacklist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-11-07","modified":"2023-05-18","description":"Detects download of certain file types from hosts in suspicious TLDs","references":["https://www.symantec.com/connect/blogs/shady-tld-research-gdn-and-our-2016-wrap","https://promos.mcafee.com/en-US/PDF/MTMW_Report.pdf","https://www.spamhaus.org/statistics/tlds/","https://krebsonsecurity.com/2018/06/bad-men-at-work-please-dont-click/"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_blacklist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"1193d960-2369-499f-a158-7b50a31df682","title":"Potential Suspicious Browser Launch From Document Reader Process","author":"Joseph Kamau","status":"test","level":"medium","date":"2024-05-27","modified":"2025-10-07","description":"Detects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.\n","references":["https://app.any.run/tasks/69c5abaa-92ad-45ba-8c53-c11e23e05d04/","https://app.any.run/tasks/64043a79-165f-4052-bcba-e6e49f847ec1/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/process_creation/proc_creation_win_susp_browser_launch_from_document_reader_process.yml","techniques":["T1204.002"],"cves":[]},{"id":"1337afba-d17d-4d23-bd55-29b927603b30","title":"Microsoft Word Add-In Loaded","author":"Steffen Rogge (dr0pd34d)","status":"test","level":"low","date":"2024-07-10","modified":null,"description":"Detects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.\n","references":["https://labs.withsecure.com/publications/add-in-opportunities-for-office-persistence","https://nored0x.github.io/red-teaming/office-persistence/#what-is-a-wll-file"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_office_word_wll_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"208748f7-881d-47ac-a29c-07ea84bf691d","title":"Suspicious Outlook Child Process","author":"Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team","status":"test","level":"high","date":"2022-02-28","modified":"2023-02-04","description":"Detects a suspicious process spawning from an Outlook process.","references":["https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100","https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/process_creation/proc_creation_win_office_outlook_susp_child_processes.yml","techniques":["T1204.002"],"cves":[]},{"id":"28208707-fe31-437f-9a7f-4b1108b94d2e","title":"Suspicious Startup Folder Persistence","author":"Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"high","date":"2022-08-10","modified":"2025-10-12","description":"Detects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors.\nThese files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers.\nThis technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.\n","references":["https://github.com/last-byte/PersistenceSniper","https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/","https://github.com/redcanaryco/atomic-red-team/blob/5ede8f21e42ebe37e0a6eff757dba60bcfa85859/atomics/T1547.001/T1547.001.md"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.execution","attack.t1204.002","attack.persistence","attack.t1547.001"],"path":"rules/windows/file/file_event/file_event_win_susp_startup_folder_persistence.yml","techniques":["T1204.002","T1547.001"],"cves":[]},{"id":"289dfa9e-e378-4a56-a9d4-7ed5ee218029","title":"Successful MSIX/AppX Package Installation","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-11-03","modified":null,"description":"Detects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log.\nWhile most installations are legitimate, this can help identify unauthorized or suspicious package installations.\nIt is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.\n","references":["https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","service":"appxdeployment-server"},"tags":["attack.execution","attack.t1204.002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/builtin/appxdeployment_server/win_appxpackaging_server_successful_package_installation.yml","techniques":["T1204.002"],"cves":[]},{"id":"29fd07fc-9cfd-4331-b7fd-cc18dfa21052","title":"Potential Maze Ransomware Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-05-08","modified":"2023-02-13","description":"Detects specific process characteristics of Maze ransomware word document droppers","references":["https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html","https://app.any.run/tasks/51e7185c-52d7-4efb-ac0d-e86340053473/","https://app.any.run/tasks/65a79440-373a-4725-8d74-77db9f2abda4/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204.002","attack.t1047","attack.impact","attack.t1490","detection.emerging-threats"],"path":"rules-emerging-threats/2020/Malware/Maze/proc_creation_win_malware_maze_ransomware.yml","techniques":["T1204.002","T1047","T1490"],"cves":[]},{"id":"3c6f5e4a-8d0b-6abc-d9e2-4f7a6b8c9d0e","title":"TanStack Supply-Chain Attack Execution Indicators - Linux","author":"Leonardo Gasparini","status":"experimental","level":"high","date":"2026-05-12","modified":null,"description":"Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.\nThe preinstall hook runs setup.mjs, which downloads a platform-specific Bun runtime.\n","references":["https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack","https://socket.dev/supply-chain-attacks/mini-shai-hulud","https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.t1059.007","attack.t1059.006","attack.t1204.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/TanStack-Supply-Chain/proc_creation_lnx_malware_tanstack_supply_chain.yml","techniques":["T1059.007","T1059.006","T1204.002"],"cves":[]},{"id":"401e5d00-b944-11ea-8f9a-00163ecd60ae","title":"AppLocker Prevented Application or Script from Running","author":"Pushkarev Dmitry","status":"test","level":"medium","date":"2020-06-28","modified":"2025-12-03","description":"Detects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.\n","references":["https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/what-is-applocker","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/using-event-viewer-with-applocker","https://nxlog.co/documentation/nxlog-user-guide/applocker.html"],"logsource":{"product":"windows","service":"applocker"},"tags":["attack.execution","attack.t1204.002","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.006","attack.t1059.007"],"path":"rules/windows/builtin/applocker/win_applocker_application_was_prevented_from_running.yml","techniques":["T1204.002","T1059.001","T1059.003","T1059.005","T1059.006","T1059.007"],"cves":[]},{"id":"438025f9-5856-4663-83f7-52f878a70a50","title":"Suspicious Microsoft Office Child Process","author":"Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io","status":"test","level":"high","date":"2018-04-06","modified":"2023-04-24","description":"Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)","references":["https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100","https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html","https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml","https://github.com/splunk/security_content/blob/300af51b88ad5d5b27ce4f5f54e4d6e6a3a2c06d/detections/endpoint/office_spawning_control.yml","https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A","https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set","https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml","https://www.vmray.com/analyses/2d2fa29185ad/report/overview.html","https://app.any.run/tasks/c903e9c8-0350-440c-8688-3881b556b8e0/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1047","attack.t1204.002","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_office_susp_child_processes.yml","techniques":["T1047","T1204.002","T1218.010"],"cves":[]},{"id":"4922a5dd-6743-4fc2-8e81-144374280997","title":"Flash Player Update from Suspicious Location","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-10-25","modified":"2022-08-08","description":"Detects a flashplayer update from an unofficial location","references":["https://gist.github.com/roycewilliams/a723aaf8a6ac3ba4f817847610935cfb"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.stealth","attack.t1189","attack.execution","attack.t1204.002","attack.t1036.005"],"path":"rules/web/proxy_generic/proxy_susp_flash_download_loc.yml","techniques":["T1189","T1204.002","T1036.005"],"cves":[]},{"id":"557e3bd3-7f21-495d-8d50-7c8bdfb8041c","title":"AppLocker Application Would Have Been Blocked","author":"heyyanu","status":"experimental","level":"medium","date":"2026-03-26","modified":null,"description":"Detects when AppLocker \"Audit only\" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker \"Enforce rules\" enforcement mode was enabled.\n","references":["https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/what-is-applocker","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/using-event-viewer-with-applocker","https://www.splunk.com/en_us/blog/security/deploy-test-monitor-mastering-microsoft-applocker-part-2.html","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ee844150(v=ws.11)"],"logsource":{"product":"windows","service":"applocker"},"tags":["attack.execution","attack.t1204.002","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.006","attack.t1059.007"],"path":"rules/windows/builtin/applocker/win_applocker_application_would_have_been_blocked.yml","techniques":["T1204.002","T1059.001","T1059.003","T1059.005","T1059.006","T1059.007"],"cves":[]},{"id":"60936b49-fca0-4f32-993d-7415edcf9a5d","title":"New Application in AppCompat","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"informational","date":"2020-05-02","modified":"2023-08-17","description":"A General detection for a new application in AppCompat. This indicates an application executing for the first time on an endpoint.","references":["https://github.com/OTRF/detection-hackathon-apt29/issues/1","https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/1.A.1_DFD6A782-9BDB-4550-AB6B-525E825B095E.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/registry/registry_set/registry_set_new_application_appcompat.yml","techniques":["T1204.002"],"cves":[]},{"id":"678eb5f4-8597-4be6-8be7-905e4234b53a","title":"Droppers Exploiting CVE-2017-11882","author":"Florian Roth (Nextron Systems)","status":"stable","level":"critical","date":"2017-11-23","modified":"2021-11-27","description":"Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe","references":["https://www.hybrid-analysis.com/sample/2a4ae284c76f868fc51d3bb65da8caa6efacb707f265b25c30f34250b76b7507?environmentId=100","https://www.linkedin.com/pulse/exploit-available-dangerous-ms-office-rce-vuln-called-thebenygreen-","https://github.com/embedi/CVE-2017-11882"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-11882","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-11882/proc_creation_win_exploit_cve_2017_11882.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-11882"]},{"id":"69483748-1525-4a6c-95ca-90dc8d431b68","title":"Suspicious Microsoft Office Child Process - MacOS","author":"Sohan G (D4rkCiph3r)","status":"test","level":"high","date":"2023-01-31","modified":"2023-02-04","description":"Detects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution","references":["https://redcanary.com/blog/applescript/","https://objective-see.org/blog/blog_0x4B.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.execution","attack.persistence","attack.t1059.002","attack.t1137.002","attack.t1204.002"],"path":"rules/macos/process_creation/proc_creation_macos_office_susp_child_processes.yml","techniques":["T1059.002","T1137.002","T1204.002"],"cves":[]},{"id":"7bdde3bf-2a42-4c39-aa31-a92b3e17afac","title":"HackTool - LittleCorporal Generated Maldoc Injection","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-08-09","modified":"2023-11-28","description":"Detects the process injection of a LittleCorporal generated Maldoc.","references":["https://github.com/connormcgarr/LittleCorporal"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.execution","attack.privilege-escalation","attack.stealth","attack.t1204.002","attack.t1055.003"],"path":"rules/windows/process_access/proc_access_win_hktl_littlecorporal_generated_maldoc.yml","techniques":["T1204.002","T1055.003"],"cves":[]},{"id":"864403a1-36c9-40a2-a982-4c9a45f7d833","title":"Exploit for CVE-2017-0261","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-02-22","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262","references":["https://www.fireeye.com/blog/threat-research/2017/05/eps-processing-zero-days.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-0261","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-0261/proc_creation_win_exploit_cve_2017_0261.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-0261"]},{"id":"8a582fe2-0882-4b89-a82a-da6b2dc32937","title":"Suspicious WmiPrvSE Child Process","author":"Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-08-23","modified":"2023-11-10","description":"Detects suspicious and uncommon child processes of WmiPrvSE","references":["https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml","https://blog.osarmor.com/319/onenote-attachment-delivers-asyncrat-malware/","https://twitter.com/ForensicITGuy/status/1334734244120309760"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1047","attack.t1204.002","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_wmiprvse_susp_child_processes.yml","techniques":["T1047","T1204.002","T1218.010"],"cves":[]},{"id":"90217a70-13fc-48e4-b3db-0d836c5824ac","title":"GAC DLL Loaded Via Office Applications","author":"Antonlovesdnb","status":"test","level":"high","date":"2020-02-19","modified":"2023-02-10","description":"Detects any GAC DLL being loaded by an Office Product","references":["https://medium.com/threatpunter/detecting-adversary-tradecraft-with-image-load-event-logging-and-eql-8de93338c16"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_dotnet_gac_dll_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"932ac737-33ca-4afd-9869-0d48b391fcc9","title":"Ursnif Malware C2 URL Pattern","author":"Thomas Patzke","status":"stable","level":"critical","date":"2019-12-19","modified":"2021-08-09","description":"Detects Ursnif C2 traffic.","references":["https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566.001","attack.execution","attack.t1204.002","attack.command-and-control","attack.t1071.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/Ursnif/proxy_malware_ursnif_c2_url.yml","techniques":["T1566.001","T1204.002","T1071.001"],"cves":[]},{"id":"9a025188-6f2d-42f8-bb2f-d3a83d24a5af","title":"Windows AppX Deployment Unsigned Package Installation","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-03","modified":null,"description":"Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events","references":["https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage","https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","service":"appxdeployment-server"},"tags":["attack.execution","attack.defense-impairment","attack.t1204.002","attack.t1553.005"],"path":"rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_unsigned_package_installation.yml","techniques":["T1204.002","T1553.005"],"cves":[]},{"id":"9a0b8719-cd3c-4f0a-90de-765a4cb3f5ed","title":"Microsoft VBA For Outlook Addin Loaded Via Outlook","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-08","modified":"2024-03-12","description":"Detects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process","references":["https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=58"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_outlook_outlvba_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"9b4f3d2e-6e8c-5fab-c7d9-2a3b4e5f6a7b","title":"TanStack Supply-Chain Attack Execution Indicators - Windows","author":"Leonardo Gasparini","status":"experimental","level":"high","date":"2026-05-12","modified":null,"description":"Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.","references":["https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack","https://socket.dev/supply-chain-attacks/mini-shai-hulud","https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.007","attack.t1204.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/TanStack-Supply-Chain/proc_creation_win_malware_tanstack_supply_chain.yml","techniques":["T1059.007","T1204.002"],"cves":[]},{"id":"9cfe4b27-1e56-48b4-b7a8-d46851c91a44","title":"MMC Executing Files with Reversed Extensions Using RTLO Abuse","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-02-05","modified":null,"description":"Detects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.","references":["https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf","https://en.wikipedia.org/wiki/Right-to-left_override","https://tria.ge/241015-l98snsyeje/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1204.002","attack.t1218.014","attack.t1036.002"],"path":"rules/windows/process_creation/proc_creation_win_mmc_rlo_abuse_pattern.yml","techniques":["T1204.002","T1218.014","T1036.002"],"cves":[]},{"id":"a7e6b1f9-8d2c-4f1e-9a7d-63e4c8a2bf4c","title":"Kapeka Backdoor Loaded Via Rundll32.EXE","author":"Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2024-07-03","modified":null,"description":"Detects the Kapeka Backdoor binary being loaded by rundll32.exe.\nThe Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.\n","references":["https://labs.withsecure.com/publications/kapeka","https://app.any.run/tasks/1efb3ed4-cc0f-4690-a0ed-24516809bc72/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.stealth","attack.t1204.002","attack.t1218.011","detection.emerging-threats"],"path":"rules-emerging-threats/2024/Malware/kapeka/image_load_malware_kapeka_backdoor_wll.yml","techniques":["T1204.002","T1218.011"],"cves":[]},{"id":"aa3a6f94-890e-4e22-b634-ffdfd54792cc","title":"Suspicious Binary In User Directory Spawned From Office Application","author":"Jason Lynch","status":"test","level":"high","date":"2019-04-02","modified":"2023-02-04","description":"Detects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)","references":["https://blog.morphisec.com/fin7-not-finished-morphisec-spots-new-campaign","https://www.virustotal.com/gui/file/23160972c6ae07f740800fa28e421a81d7c0ca5d5cab95bc082b4a986fbac57"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1204.002","attack.g0046","car.2013-05-002"],"path":"rules/windows/process_creation/proc_creation_win_office_spawn_exe_from_users_directory.yml","techniques":["T1204.002"],"cves":[]},{"id":"af4c4609-5755-42fe-8075-4effb49f5d44","title":"Microsoft Excel Add-In Loaded From Uncommon Location","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-12","modified":null,"description":"Detects Microsoft Excel loading an Add-In (.xll) file from an uncommon location","references":["https://www.mandiant.com/resources/blog/lnk-between-browsers","https://wazuh.com/blog/detecting-xll-files-used-for-dropping-fin7-jssloader-with-wazuh/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_excel_xll_susp_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"af5732ed-764e-489d-826d-0447c8b36242","title":"Windows MSIX Package Support Framework AI_STUBS Execution","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-11-03","modified":null,"description":"Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'.\nThis activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.\n","references":["https://redcanary.com/blog/threat-intelligence/msix-installers/","https://redcanary.com/threat-detection-report/techniques/installer-packages/","https://learn.microsoft.com/en-us/windows/msix/package/package-support-framework","https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.defense-impairment","attack.t1218","attack.t1553.005","attack.t1204.002"],"path":"rules/windows/process_creation/proc_creation_win_msix_ai_stub_execution.yml","techniques":["T1218","T1553.005","T1204.002"],"cves":[]},{"id":"b5de2919-b74a-4805-91a7-5049accbaefe","title":"Download From Suspicious TLD - Whitelist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-03-13","modified":"2023-05-18","description":"Detects executable downloads from suspicious remote systems","references":["Internal Research"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_whitelist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"c5f4b5cb-4c25-4249-ba91-aa03626e3185","title":"Microsoft Excel Add-In Loaded","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-05-12","modified":null,"description":"Detects Microsoft Excel loading an Add-In (.xll) file","references":["https://www.mandiant.com/resources/blog/lnk-between-browsers"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_office_excel_xll_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"c7a74c80-ba5a-486e-9974-ab9e682bc5e4","title":"File With Uncommon Extension Created By An Office Application","author":"Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-08-23","modified":"2025-10-17","description":"Detects the creation of files with an executable or script extension by an Office application.","references":["https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.t1204.002","attack.execution"],"path":"rules/windows/file/file_event/file_event_win_office_susp_file_extension.yml","techniques":["T1204.002"],"cves":[]},{"id":"d13c43f0-f66b-4279-8b2c-5912077c1780","title":"CLR DLL Loaded Via Office Applications","author":"Antonlovesdnb","status":"test","level":"medium","date":"2020-02-19","modified":"2023-03-29","description":"Detects CLR DLL being loaded by an Office Product","references":["https://medium.com/threatpunter/detecting-adversary-tradecraft-with-image-load-event-logging-and-eql-8de93338c16"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_dotnet_clr_dll_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"dd8756e7-a3a0-4768-b47e-8f545d1a751c","title":"Suspicious LNK Command-Line Padding with Whitespace Characters","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-03-19","modified":null,"description":"Detects exploitation of LNK file command-line length discrepancy, where attackers hide malicious commands beyond the 260-character UI limit while the actual command-line argument field supports 4096 characters using whitespace padding (e.g., 0x20, 0x09-0x0D).\nAdversaries insert non-printable whitespace characters (e.g., Line Feed \\x0A, Carriage Return \\x0D) to pad the visible section of the LNK file, pushing malicious commands past the UI-visible boundary.\nThe hidden payload, executed at runtime but invisible in Windows Explorer properties, enables stealthy execution and evasion—commonly used for social engineering attacks.\nThis rule flags suspicious use of such padding observed in real-world attacks.\n","references":["https://syedhasan010.medium.com/forensics-analysis-of-an-lnk-file-da68a98b8415","https://thehackernews.com/2025/03/unpatched-windows-zero-day-flaw.html","https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.execution","attack.t1204.002"],"path":"rules/windows/process_creation/proc_creation_win_susp_lnk_exec_hidden_cmd.yml","techniques":["T1204.002"],"cves":[]},{"id":"e1693bc8-7168-4eab-8718-cdcaa68a1738","title":"Suspicious WMIC Execution Via Office Process","author":"Vadim Khrykov, Cyb3rEng","status":"test","level":"high","date":"2021-08-23","modified":"2023-02-14","description":"Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).","references":["https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1204.002","attack.t1047","attack.t1218.010","attack.execution"],"path":"rules/windows/process_creation/proc_creation_win_wmic_susp_execution_via_office_process.yml","techniques":["T1204.002","T1047","T1218.010"],"cves":[]},{"id":"e54279c7-4910-4e2c-902c-c56a25b549f6","title":"Windows AppX Deployment Full Trust Package Installation","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-03","modified":null,"description":"Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions","references":["https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","service":"appxdeployment-server"},"tags":["attack.execution","attack.defense-impairment","attack.t1204.002","attack.t1553.005"],"path":"rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_full_trust_package_installation.yml","techniques":["T1204.002","T1553.005"],"cves":[]},{"id":"e6ce8457-68b1-485b-9bdd-3c2b5d679aa9","title":"VBA DLL Loaded Via Office Application","author":"Antonlovesdnb","status":"test","level":"high","date":"2020-02-19","modified":"2023-02-10","description":"Detects VB DLL's loaded by an office application. Which could indicate the presence of VBA Macros.","references":["https://medium.com/threatpunter/detecting-adversary-tradecraft-with-image-load-event-logging-and-eql-8de93338c16"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_vbadll_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"f40017b3-cb2e-4335-ab5d-3babf679c1de","title":"Remote DLL Load Via Rundll32.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-09-18","modified":null,"description":"Detects a remote DLL load event via \"rundll32.exe\".","references":["https://github.com/gabe-k/themebleed","Internal Research"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_rundll32_remote_share_load.yml","techniques":["T1204.002"],"cves":[]},{"id":"fdd84c68-a1f6-47c9-9477-920584f94905","title":"Exploit for CVE-2017-8759","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2017-09-15","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759","references":["https://www.hybrid-analysis.com/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100","https://www.reverse.it/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-8759","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-8759/proc_creation_win_exploit_cve_2017_8759.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-8759"]},{"id":"ff0f2b05-09db-4095-b96d-1b75ca24894a","title":"DotNET Assembly DLL Loaded Via Office Application","author":"Antonlovesdnb","status":"test","level":"medium","date":"2020-02-19","modified":"2023-03-29","description":"Detects any assembly DLL being loaded by an Office Product","references":["https://medium.com/threatpunter/detecting-adversary-tradecraft-with-image-load-event-logging-and-eql-8de93338c16"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.t1204.002"],"path":"rules/windows/image_load/image_load_office_dotnet_assembly_dll_load.yml","techniques":["T1204.002"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-27363","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-38080","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-21608","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-26369","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-36884","state":"stale","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-21715","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-34713","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-30190","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2018-4990","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2012-0754","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2011-2462","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2010-2883","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2010-1297","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2009-4324","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2009-3953","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2009-1862","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2008-0655","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2007-5659","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2016-0984","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2015-3113","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2017-11292","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2016-4117","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2015-7645","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2015-3043","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2014-0496","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2013-0641","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2012-1535","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2011-0611","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2008-2992","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2018-15982","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-21017","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-28550","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2018-4878","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}