Techniques › T1684
T1684 Social Engineering
stealth — Linux, macOS, Office Suite, SaaS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
5
analytics
0
Sigma rules tagged attack.t1684
0
KEV CVEs mapped here
<p>Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators.</p><p>Adversaries may leverage trust-building methods across multiple channels (e.g., executive, vendor, or help desk scenarios, including AI-enabled voice interactions) to prompt user-authorized actions such as password resets, MFA changes, financial approvals, or the disclosure of sensitive information. Adversaries may also leverage common business communications and workflows such as email, collaboration platforms, voice communications, recruiting processes, help desk interactions, and SaaS consent mechanisms to make malicious requests appear routine and legitimate.</p><p>Additionally, adversaries have persuaded victims to take actions through references of current events, harnessing relevant themes to the work role or the organizations mission. For example, adversaries may use scare tactics (i.e., threaten repercussions for non-compliance) or otherwise incite victims’ emotions in order to generate a sense of urgency to take action.</p><p>This technique may include common social engineering patterns such as Phishing and Spearphishing Voice, often supported by convincing and targeted narratives.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0899 Detect Social Engineering v1.0
AN2037 LinuxDetects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.NSM:Connections
Outbound connection after script or installer launch→ DC0082 Network Connection Creationauditd:EXECVEexecve of curl,wget,bash,sh,python with piped or remote content→ DC0064 Command ExecutionTunable:RemoteScriptExecutionPatternsTicketToExecutionWindowAN2035 WindowsDetects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.Tunable:EmailToExecutionWindowOfficeChildProcessAllowlistNewLogonWindowAN2034 SaaSDetects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.saas:oktauser.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize→ DC0002 User Account Authenticationsaas:slackxternal DM or workspace invite preceding credential or approval actions→ DC0038 Application Log Contentsaas:zoomUnexpected contact interaction preceding follow-on admin requests→ DC0038 Application Log ContentTunable:RequesterNoveltyDaysGeoVelocityThresholdAfterHoursDefinitionAN2033 Office SuiteDetects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.m365:unifiedMailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet→ DC0038 Application Log Contentm365:exchangeExternal sender message followed by user action involving links or attachments→ DC0038 Application Log Contentm365:teamsExternal chat request or new tenant communication preceding approval activity→ DC0038 Application Log ContentTunable:ActionAfterMessageWindowTrustedDomainAllowlistApprovalAmountThresholdAN2036 macOSDetects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.NSM:ConnectionsOutbound connection after script or installer launch→ DC0082 Network Connection CreationTunable:DownloadToExecutionWindowInstallerParentAllowlist
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1684
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.