Suspicious process execution from archive via shortcut file
Detects suspicious process execution triggered by a shortcut (.lnk) file extracted from an archive. Adversaries can employ in user-execution attacks where malicious payloads are hidden inside archives and launched via decoy shortcut files to evade detection.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Ejecución
- Técnicas MITRE: T1204, T1204.002