Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.001

T1204.001Malicious Link

T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 12 detection use cases covering it and 184 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
184Articles
0Sub-techniques
1Tactic

Use cases covering this technique (12)

Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD Windows ISO LNK File Creation ESCU actions · hunting P Windows PowerShell FakeCAPTCHA Clipboard Execution ESCU actions · alerting P [LLM] Quishing delivery: inbound email with QR-code image/PDF attachment and no scannable body URL Bespoke delivery · hunting DSP [LLM] JWR phishing-kit landing: victim beacon + ws-worker.js load in web proxy telemetry Bespoke delivery · alerting DSΣP [LLM] Safe Links click resolving through a cloud-PaaS redirect chain into AitM phishing Bespoke delivery · hunting DS [LLM] ClickFix execution reaching CaptiveCrunch infrastructure or dropping svchost32 Bespoke delivery · alerting DSΣPDDCS [LLM] QR-code PDF phishing attachment resolving to workers.dev / pamconj M365 harvesting page (UAT-11764) Bespoke delivery · alerting DS [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD

Articles citing this technique (184)