Suspicious process execution from archive via shortcut file
Detects suspicious process execution triggered by a shortcut (.lnk) file extracted from an archive. Adversaries can employ in user-execution attacks where malicious payloads are hidden inside archives and launched via decoy shortcut files to evade detection.
- Platform: Windows
- Severity: High
- MITRE Tactic: Execution
- MITRE Techniques: T1204, T1204.002