Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0021 — OS API Execution
DC0021

OS API Execution

66 analytic(s) · 54 detection strategy(ies)

Description

Calls made by a process to operating system-provided Application Programming Interfaces (APIs). These calls are essential for interacting with system resources such as memory, files, and hardware, or for performing system-level tasks. Monitoring these calls can provide insight into a process's intent, especially if the process is malicious.

Referenced in Analytics

66
AN0119 Analytic 0119 DET0043

Unusual process or API usage attempting to query system locale, timezone, or keyboard layout (e.g., calls to GetLocaleInfoW, GetTimeZoneInformation). Detection can be enhanced by correlating with processes not typically associated with system configuration queries, such as unknown binaries or scripts.

WinEventLog:Security etw:Microsoft-Windows-Kernel-Base
AN0122 Analytic 0122 DET0043

Detection of queries to instance metadata services (e.g., AWS IMDS, Azure Metadata Service) for availability zone, region, or network geolocation details. Correlation with non-management accounts or non-standard workloads may indicate adversary reconnaissance.

AWS:CloudTrail azure:vpcflow
AN0164 Analytic 0164 DET0059

Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.

macos:unifiedlog macos:osquery
AN0244 Analytic 0244 DET0089

Detects non-system processes accessing /dev/input/* or issuing ptrace/evdev syscalls used for reading keystroke buffers directly.

auditd:SYSCALL auditd:SYSCALL
AN0250 Analytic 0250 DET0091

Behavioral chain involving suspicious use of GetProcAddress and LoadLibrary following memory allocation and manual mapping, often paired with low entropy strings, abnormal API use without static import tables, or delayed module load behaviors.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN0257 Analytic 0257 DET0093

Adversary executes CLI commands like `show users`, `show ssh`, or attempts to dump AAA user lists from routers or switches.

networkdevice:syslog networkdevice:syslog
AN0273 Analytic 0273 DET0097

Processes that utilize AppleScript, `CGWindowListCopyWindowInfo`, or `NSRunningApplication` APIs to list active application windows and foreground processes.

macos:unifiedlog macos:osquery
AN0277 Analytic 0277 DET0100

Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process WinEventLog:Sysmon
AN0283 Analytic 0283 DET0102

Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0340 Analytic 0340 DET0121

Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains.

macos:unifiedlog macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0374 Analytic 0374 DET0132

User-mode application uses flock() or NSDistributedLock to gain exclusive access to a resource file (e.g., /tmp/guard.lock), conditional logic alters execution if already locked.

macos:unifiedlog macos:unifiedlog
AN0383 Analytic 0383 DET0136

Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection.

WinEventLog:Security WinEventLog:Security etw:Microsoft-Windows-Directory-Services-SAM
AN0398 Analytic 0398 DET0141

Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity.

macos:unifiedlog WinEventLog:Sysmon
AN0430 Analytic 0430 DET0151

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-Kernel-Process WinEventLog:TaskScheduler WinEventLog:TaskScheduler EDR:Telemetry
AN0431 Analytic 0431 DET0151

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

auditd:SYSCALL auditd:SYSCALL linux:syslog linux:cron
AN0497 Analytic 0497 DET0175

Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts.

networkdevice:config networkdevice:syslog NSM:Flow
AN0513 Analytic 0513 DET0182

Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-RPC
AN0514 Analytic 0514 DET0182

CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0568 Analytic 0568 DET0197

A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Microsoft-Windows-Windows Camera Frame Server/Operational
AN0569 Analytic 0569 DET0197

A process opens/reads /dev/video* (V4L2), performs ioctl/read loops, writes large/continuous video artifacts to disk, and/or quickly establishes outbound connections for exfiltration.

auditd:SYSCALL auditd:SYSCALL linux:osquery linux:syslog NSM:Flow
AN0570 Analytic 0570 DET0197

A non-whitelisted process receives TCC camera entitlement (kTCCServiceCamera), opens AppleCamera/AVFoundation device handles, writes .mov/.mp4 artifacts to unusual locations, and/or beacons/exfiltrates soon after.

macos:unifiedlog macos:endpointsecurity macos:endpointsecurity macos:unifiedlog
AN0579 Analytic 0579 DET0203

Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0580 Analytic 0580 DET0204

Detects suspicious registry modifications under `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\Windows\System32` not tied to known patches or installations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application
AN0608 Analytic 0608 DET0217

Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.

WinEventLog:Sysmon etw:Microsoft-Windows-Win32k WinEventLog:Security
AN0613 Analytic 0613 DET0219

Detection of Linux container escape attempts via syscalls (`unshare`, `keyctl`, `mount`) or process execution outside container namespaces. Defenders may correlate unusual system calls from containerized processes with subsequent process creation on the host or modification of host resources.

auditd:SYSCALL linux:Sysmon
AN0621 Analytic 0621 DET0221

Processes invoking AVFoundation or CoreAudio frameworks, accessing input devices via TCC logs or Unified Logs, followed by writing AIFF/WAV/MP3 files to disk.

macos:unifiedlog Apple TCC Logs fs:fsusage
AN0622 Analytic 0622 DET0222

Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-COM/Operational WinEventLog:Sysmon WinEventLog:PowerShell
AN0689 Analytic 0689 DET0246

Processes accessing TCC-protected input APIs or polling HID services without user interaction, or dynamically loaded keylogging frameworks using accessibility privileges

macos:unifiedlog macos:osquery
AN0703 Analytic 0703 DET0254

Detect alterations of transmitted data via monitoring syscalls (`send`, `recv`, `write`) or middleware interception. Identify mismatched file hashes when compared at origin vs. destination. Watch for anomalous activity from processes interacting with secure transmission services (e.g., OpenSSL, scp).

auditd:SYSCALL linux:syslog
AN0704 Analytic 0704 DET0254

Monitor system APIs such as CFNetwork and SecureTransport for anomalies in transmitted data streams. Detect mismatches in file hashes or SSL/TLS downgrade attempts that enable manipulation of transmitted data.

macos:unifiedlog macos:osquery
AN0786 Analytic 0786 DET0283

Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon ETW:Token WinEventLog:Security
AN0822 Analytic 0822 DET0295

Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread).

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process WinEventLog:Sysmon
AN0838 Analytic 0838 DET0300

Detect anomalous chains of memory allocation and execution inside the same process (e.g., VirtualAlloc → memcpy → VirtualProtect → CreateThread). Unlike process injection, reflective code loading does not perform cross-process memory writes — the suspicious activity occurs entirely within the process’s own PID context.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-DotNETRuntime etw:Microsoft-Antimalware-Scan-Interface WinEventLog:Sysmon
AN0839 Analytic 0839 DET0300

Monitor for in-process mmap + mprotect + execve/execveat activity where memory permissions are changed from writable to executable inside the same process without a corresponding ELF on disk.

auditd:SYSCALL auditd:MMAP
AN0907 Analytic 0907 DET0320

Detects interactive or automated use of CLI commands like `show ip sockets`, `show tcp brief`, or SNMP queries for active sessions on routers/switches.

networkdevice:cli snmp:trap
AN0908 Analytic 0908 DET0320

Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).

AWS:CloudTrail azure:activity
AN0941 Analytic 0941 DET0331

Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Win32k
AN0976 Analytic 0976 DET0345

Monitor audit logs for setuid/setgid bit changes, executions where UID ≠ EUID (indicative of sudo or privilege escalation), and high-integrity binaries launched by unprivileged users.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0977 Analytic 0977 DET0345

Detect execution of `/usr/libexec/security_authtrampoline` or use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges.

macos:unifiedlog auditd:SYSCALL fs:fsusage
AN1045 Analytic 1045 DET0371

Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts.

WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1047 Analytic 1047 DET0371

Detect suspicious calls to sysctl or ptrace API used to determine if a process is being debugged. Monitor for processes that flood OutputDebugString equivalents or generate abnormal exceptions to evade analysis.

macos:unifiedlog
AN1068 Analytic 1068 DET0378

Detects encoded PowerCLI or Base64-encoded payloads staged via datastore uploads or shell access (e.g., ESXi Shell or backdoored VIBs).

esxi:vmkernel esxi:hostd
AN1076 Analytic 1076 DET0382

Detects adversary use of suspended process creation, using the CREATE_SUSPENDED flag via CreateProcess, followed by unmapping the memory of the child process (NtUnmapViewOfSection) and replacing it with malicious code via VirtualAllocEx/WriteProcessMemory, then SetThreadContext and ResumeThread to begin execution within the hollowed process.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1098 Analytic 1098 DET0391

Detect runtime manipulation by monitoring system calls for modifications to shared libraries, ELF binaries, or environment variables that affect how data is displayed. Look for suspicious writes to application directories and mismatch in binary integrity baselines.

auditd:SYSCALL linux:syslog
AN1111 Analytic 1111 DET0395

Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1112 Analytic 1112 DET0396

Detects suspicious access to macOS Keychain files and APIs. Observes processes invoking the 'security' utility or accessing Keychain databases directly, correlates these with abnormal parent process lineage or unexpected user context. Monitors attempts to dump, unlock, or read credential storage beyond normal application workflows.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1184 Analytic 1184 DET0420

API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState).

macos:unifiedlog macos:unifiedlog
AN1196 Analytic 1196 DET0428

Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context.

auditd:SYSCALL auditd:PATH linux:osquery
AN1201 Analytic 1201 DET0430

Detects attempts to access or enumerate cloud password/secrets storage services such as AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager. Monitors API calls for abnormal enumeration or bulk retrieval of secrets.

AWS:CloudTrail AWS:CloudTrail
AN1206 Analytic 1206 DET0432

Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-File
AN1223 Analytic 1223 DET0443

Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis.

auditd:SYSCALL auditd:SYSCALL
AN1224 Analytic 1224 DET0443

Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using `daemon()`, `fork()` or background execution flags.

macos:unifiedlog fs:fsusage
AN1241 Analytic 1241 DET0448

Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace.

auditd:SYSCALL auditd:memprotect auditd:file-events linux:osquery
AN1253 Analytic 1253 DET0456

A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions.

WinEventLog:Security WinEventLog:Sysmon ETW:ProcThread WinEventLog:Security WinEventLog:Security
AN1289 Analytic 1289 DET0467

Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon EDR:memory
AN1324 Analytic 1324 DET0482

Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context.

WinEventLog:Security WinEventLog:Sysmon ETW:Token
AN1351 Analytic 1351 DET0489

A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM.

WinEventLog:Security etw:Microsoft-Windows-Kernel-Process etw:Microsoft-Windows-Kernel-Process
AN1375 Analytic 1375 DET0498

A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement.

WinEventLog:Security WinEventLog:Security etw:Microsoft-Windows-Security-Auditing
AN1399 Analytic 1399 DET0508

Detects process injection by correlating memory manipulation API calls (e.g., VirtualAllocEx, WriteProcessMemory), suspicious thread creation (e.g., CreateRemoteThread), and unusual DLL loads within another process's context.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1400 Analytic 1400 DET0508

Detects ptrace- or memfd-based process injection through audit logs capturing system calls (e.g., ptrace, mmap) targeting running processes along with suspicious file descriptors or memory writes.

auditd:SYSCALL auditd:SYSCALL linux:procfs
AN1494 Analytic 1494 DET0541

Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1501 Analytic 1501 DET0544

Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1561 Analytic 1561 DET0565

Registry access to system language keys (e.g., HKLM\SYSTEM\CurrentControlSet\Control\Nls\Language) or suspicious processes invoking locale-related APIs (e.g., GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList). Defender visibility focuses on anomalous or non-standard processes issuing these queries, especially when run by unknown binaries or scripts.

WinEventLog:Security WinEventLog:Sysmon ETW
AN1593 Analytic 1593 DET0577

Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1626 Analytic 1626 DET0591

Detects attempts to modify file timestamps via API usage (e.g., `SetFileTime`), CLI tools (e.g., `w32tm`, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted.

WinEventLog:Sysmon WinEventLog:Security EDR:file
AN2029 Analytic 2029 DET0898

Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators. User-Agent strings can be gathered with API calls such as `ShellExecuteW` to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser.

NSM:Flow WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process

Detection Strategies

54
DET0043 Detection Strategy for System Location Discovery DET0059 Detection Strategy for Data Manipulation DET0089 Behavioral Detection of Keylogging Activity Across Platforms DET0091 Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups DET0093 Behavioral Detection of User Discovery via Local and Remote Enumeration DET0097 Detection of Application Window Enumeration via API or Scripting DET0100 Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing DET0102 Behavioral Detection of Input Capture Across Platforms DET0121 Detection Strategy for T1547.015 – Login Items on macOS DET0132 Detection of Mutex-Based Execution Guardrails Across Platforms DET0136 Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows) DET0141 Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution DET0151 Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery DET0175 Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit DET0182 Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS DET0197 Behavior-chain, platform-aware detection strategy for T1125 Video Capture DET0203 Detection Strategy for Ptrace-Based Process Injection on Linux DET0204 Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows) DET0217 Detection Strategy for Extra Window Memory (EWM) Injection on Windows DET0219 Detection Strategy for Escape to Host DET0221 Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS DET0222 Detecting MMC (.msc) Proxy Execution and Malicious COM Activation DET0246 Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying DET0254 Detection Strategy of Transmitted Data Manipulation DET0283 Behavior-chain detection for T1134 Access Token Manipulation on Windows DET0295 Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching DET0300 Detection Strategy for Reflective Code Loading DET0320 Detection of System Network Connections Discovery Across Platforms DET0331 Detection Strategy for ListPlanting Injection on Windows DET0345 Detection Strategy for Abuse Elevation Control Mechanism (T1548) DET0371 Detection Strategy for Debugger Evasion (T1622) DET0378 Behavioral Detection of Obfuscated Files or Information DET0382 Detection Strategy for Process Hollowing on Windows DET0391 Detection Strategy for Runtime Data Manipulation. DET0395 macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection DET0396 Detect Access to macOS Keychain for Credential Theft DET0420 Detect User Activity Based Sandbox Evasion via Input & Artifact Probing DET0428 Detection Strategy for Bind Mounts on Linux DET0430 Detect Credentials Access from Password Stores DET0432 Detection Strategy for NTFS File Attribute Abuse (ADS/EAs) DET0443 Detection Strategy for Masquerading via Breaking Process Trees DET0448 Detection Strategy for VDSO Hijacking on Linux DET0456 Behavior-chain detection for T1134.002 Create Process with Token (Windows) DET0467 Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing DET0482 Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows DET0489 Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows) DET0498 Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows) DET0508 Behavioral Detection of Process Injection Across Platforms DET0541 Detection Strategy for /proc Memory Injection on Linux DET0544 Detection Strategy for Process Doppelgänging on Windows DET0565 Detection Strategy for System Language Discovery DET0577 Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows. DET0591 Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering DET0898 Detection of Spoofed User-Agent

Details

MITRE ID
DC0021
STIX ID
x-mitre-data-component--9bde2f9d-a695-4344-bfac-f2dce13d121e
Analytics
66
Detection Strategies
54
Leaving Threaticon

This link opens an external site that isn't part of the platform.