Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0467 — Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing
DET0467

Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1289 Analytic 1289
Windows

Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution.

WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=8 EDR:memory MemoryWriteToExecutable
[TargetProcessFilter] Subset of processes whose TLS callbacks should not change post-load (e.g., explorer.exe, lsass.exe)
[TimeWindowBetweenLoadAndTLSModification] Acceptable delay between image load and memory tampering in .tls or .data sections
[AnomalousThreadStartThreshold] Number of threads executing prior to main entry point that is considered suspicious
[PayloadEntropyThreshold] Optional threshold to distinguish injected shellcode from benign memory writes

Detected Techniques

1

Details

MITRE ID
DET0467
STIX ID
x-mitre-detection-strategy--a14db1ea-e57e-4bc4-83bb-94a6e7da87b0
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.