Analytics BIOC
Low
✕
Office process accessed an unusual .LNK file
An attacker may embed a .LNK file in an Office document to execute malicious code.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
ATT&CK techniques: User Execution (T1204) Boot or Logon Autostart Execution: Shortcut Modification (T1547.009)
Attacker's goals:
Modify or create a shortcut to gain code or program execution.
Investigative actions:
Check if the Office document contains a shortcut object. Check the content (strings) of the document object for a .LNK shortcut. Check the content of the shortcut.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days