Skip to content
CYBER DEFENSE MONITOR
Cyronix Intelligence Core
Dashboard
Intelligence
Live Map
News
Threat Actors
Tools
Blog
Contact
--:--:-- UTC
ELEVATED
Secure Perimeter
Dashboard
/
Intelligence
/
ATT&CK
/
T1204
User Execution
MITRE ATT&CK
T1204
Summary
Relying on a user to open a file or link that runs the attacker's code.
Tactics
TA0002
Execution
Tracked actors using this technique (2)
APT33
Iran (state-aligned)
Espionage
Lazarus Group
North Korea (state-sponsored)
Financial
Reference
View on MITRE ATT&CK
Generate detection rule →
← Full ATT&CK matrix
Threat actor encyclopedia