Basyrix SOC Response Atlas by Basyrix

Initial Access · Command and Control

T1659 — Content Injection

Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic...

Investigate Content Injection activity in the context of Initial Access/Command and Control: confirm scope, affected host/identity, and whether it matches expected administrative behaviour before deciding this is benign.

Platforms

Linux, macOS, Windows

Priority / status

medium / draft

Evidence to collect

  • Host or resource affected
  • Account or identity involved
  • Timestamp of the activity
  • Related process, file, or network artifact
  • Any preceding or follow-on alerts