Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0389 — Behavioral Detection of DLL Injection via Windows API
DET0389

Behavioral Detection of DLL Injection via Windows API

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1095 Analytic 1095
Windows

Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading.

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=17
[InjectedDLLSignatureStatus] Whether the DLL is unsigned, untrusted, or loaded from a non-standard path
[TimeWindow] Temporal correlation threshold between memory operations and thread creation
[TargetProcessList] List of sensitive or high-value processes targeted for injection (e.g., explorer.exe, winlogon.exe)
[ParentProcessAnomalyThreshold] Degree of deviation from expected parent-child lineage

Detected Techniques

1

Details

MITRE ID
DET0389
STIX ID
x-mitre-detection-strategy--e9c54806-2d8e-4722-805c-4a1e7f6a1986
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.