Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0331 — Detection Strategy for ListPlanting Injection on Windows
DET0331

Detection Strategy for ListPlanting Injection on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0941 Analytic 0941
Windows

Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory.

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=8 WinEventLog:Sysmon EventCode=1 etw:Microsoft-Windows-Win32k SendMessage, PostMessage, LVM_*
[TimeWindow_PostMessage_to_LVM_SORTITEMS] Defines temporal distance between payload copy and execution trigger
[TargetWindowClassName] Restrict detection to SysListView32 or similar GUI elements
[UserContextAnomalyThreshold] Adjusts detection sensitivity to users sending window messages across session boundaries
[InterprocessWindowMessagingFrequency] Raise alert when rate of message-passing to foreign GUI processes exceeds baseline

Detected Techniques

1

Details

MITRE ID
DET0331
STIX ID
x-mitre-detection-strategy--175b97d9-287e-4ab6-ae95-8652c224f02a
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.