Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.001

T1204.001Malicious Link

T1204.001 — Malicious Link is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 9 detection use cases covering it and 130 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
9Use cases
130Articles
0Sub-techniques
1Tactic

Use cases covering this technique (9)

Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP User clicked through a Safe Links warning page Internal delivery · alerting DS Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD Windows ISO LNK File Creation ESCU actions · hunting P Windows PowerShell FakeCAPTCHA Clipboard Execution ESCU actions · alerting P [LLM] Phishing email click landing on Sniper Dz infrastructure (URL/click correlation) Bespoke delivery · alerting DSPDD [LLM] PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke delivery · hunting DSΣPDD [LLM] User-targeted SvelteSpill exploit URL delivered or clicked (CVE-2026-27118) Bespoke delivery · alerting DSΣPDD

Articles citing this technique (130)