Detection of Project File Infection

Technique Detected:  Project File Infection | T0873

ID: DET0766
Domains: ICS
Analytics: AN1898
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1898

Monitor for unexpected changes to project files, although if the malicious modification occurs in tandem with legitimate changes it will be difficult to isolate the unintended changes by analyzing only file systems modifications.

Log Sources
Data Component Name Channel
File Modification (DC0061) File None