AN1289
Analytic 1289
Windows
Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution.
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=10
WinEventLog:Sysmon
EventCode=8
EDR:memory
MemoryWriteToExecutable
[TargetProcessFilter]
Subset of processes whose TLS callbacks should not change post-load (e.g., explorer.exe, lsass.exe)
[TimeWindowBetweenLoadAndTLSModification]
Acceptable delay between image load and memory tampering in .tls or .data sections
[AnomalousThreadStartThreshold]
Number of threads executing prior to main entry point that is considered suspicious
[PayloadEntropyThreshold]
Optional threshold to distinguish injected shellcode from benign memory writes