For the complete documentation index, see llms.txt. This page is also available as Markdown.

Office process accessed an unusual .LNK file

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

7 Days

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Execution (TA0002), Persistence (TA0003)

ATT&CK Technique

User Execution (T1204), Boot or Logon Autostart Execution: Shortcut Modification (T1547.009)

Severity

Low

Description

An attacker may embed a .LNK file in an Office document to execute malicious code.

Attacker's Goals

Modify or create a shortcut to gain code or program execution.

Investigative actions

  • Check if the Office document contains a shortcut object.

  • Check the content (strings) of the document object for a .LNK shortcut.

  • Check the content of the shortcut.

Was this helpful?