Threadlinqs IntelligenceStart free

ATT&CK techniqueExecution

T1204 User Execution

ExecutionEnterprise

As of 2026-10-05, T1204 (User Execution) appears in 571 tracked threats, first reported 2022-04-07 and most recently 2026-09-29, with linked actors including APT38, Lazarus Group, Contagious Interview; it most often appears alongside T1071 (Application Layer Protocol).

Tracked threats
571123 critical, 384 high, 60 medium, 2 low
First seen
2022-04-07
Last seen
2026-09-29
Threat actors
132In the threats using it
Detection rules
249Blue tier and above

Data as of:

Activity timeline

T1204 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 167 reports, and 570 of the 571 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1204 User Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 571 of 2623 tracked threats (21.8%) to it; by severity that is 123 critical, 384 high, 60 medium, 2 low.

Threats that use T1204 most often also use T1071 Application Layer Protocol (420 threats), T1027 Obfuscated Files or Information (416 threats), T1059 Command and Scripting Interpreter (393 threats), T1036 Masquerading (392 threats), T1566 Phishing (362 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

132 tracked threat actors appear in the threats that use T1204; the most frequent are APT38 (17), Lazarus Group (14), Contagious Interview (13), Sapphire Sleet (13), Stardust Chollima (13).

Mitigations

MITRE ATT&CK lists 6 mitigations for T1204.

Data sources

Telemetry that can reveal T1204, per MITRE ATT&CK.

  • Application Log — Application Log Content
  • Command — Command Execution
  • Container — Container Creation, Container Start
  • File — File Creation
  • Image — Image Creation
  • Instance — Instance Creation, Instance Start
  • Network Traffic — Network Connection Creation, Network Traffic Content
  • Process — Process Creation

Threat actors using it

Tracked threats

The 30 most recent of 571 tracked threats that use T1204.

Detection coverage

Threadlinqs maintains 249 detection rules mapped to T1204 (SPL 89, KQL 81, Sigma 78, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

249 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques