Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.001

T1204.001Malicious Link

T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 12 detection use cases covering it and 177 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
177Articles
0Sub-techniques
1Tactic

Use cases covering this technique (12)

Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD Windows ISO LNK File Creation ESCU actions · hunting P Windows PowerShell FakeCAPTCHA Clipboard Execution ESCU actions · alerting P [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact Bespoke delivery · alerting DSΣPDDCS [LLM] InsureTrap malvertising: Google Ads referrer landing on free-hosting insurance phish Bespoke delivery · hunting DSΣP [LLM] ChatGPT AgentForger CSRF link: Agent Builder URL with initial_assistant_prompt param Bespoke delivery · alerting DSΣP [LLM] Financial_report.bat dropper downloaded from ClickUp attachment host Bespoke delivery · alerting DSΣPDDCS [LLM] Joro proxy-mode confused-deputy: browser POSTs to loopback API 127.0.0.1:9090 (CVE-2026-53649) Bespoke delivery · hunting DSΣPCS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD

Articles citing this technique (177)