Skip to content
← LibraryTechnique entry
T1204Execution

User Execution

Rely on a user opening a malicious file or link.

§ Where this technique fits

T1204 is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 15 approved dossiers in the registry, typically at step 3.3 on average.

Authoritative reference: attack.mitre.org/techniques/T1204/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 2×
  2. 02
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  3. 03
    AAD Token Cache Exfil
    M365-TOKEN-EXFIL · Credential Access
    seen 1×
  4. 04
    AITM Phishing — Evilginx / Modlishka
    PH-AITM-EVILGINX · Initial Access
    seen 1×
  5. 05
    EternalBlue (MS17-010 / CVE-2017-0144)
    CVE-ETERNALBLUE · Initial Access
    seen 1×
  6. 06
    Indirect Prompt Injection (RAG / Web)
    AI-INDIRECT-INJECT · Initial Access
    seen 1×
  7. 07
    LaunchAgent / LaunchDaemon Persistence
    MAC-LAUNCHAGENT · Persistence
    seen 1×
  8. 08
    Malicious MCP Server
    AI-MCP-SERVER · Initial Access
    seen 1×