Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0577 — Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.
DET0577

Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1593 Analytic 1593
Windows

Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=1 etw:Microsoft-Windows-Kernel-Process WriteProcessMemory: WriteProcessMemory targeting regions containing KernelCallbackTable addresses
[MonitoredProcesses] GUI applications (e.g., explorer.exe, notepad.exe) where KernelCallbackTable abuse is more likely.
[CallbackFunctions] Specific callback functions (e.g., fnCOPYDATA, fnDWORD) expected to remain stable.
[TimeWindow] Correlation interval between WriteProcessMemory calls and execution of modified callback functions.
[AccessMaskThresholds] Access rights values that should be flagged when targeting GUI processes.

Detected Techniques

1

Details

MITRE ID
DET0577
STIX ID
x-mitre-detection-strategy--7ee8426e-2b65-44ed-b6d4-3800b92adf2e
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.