Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0336 — Detect Compromise of Host Software Binaries
DET0336

Detect Compromise of Host Software Binaries

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0949 Analytic 0949
Windows

Monitors for unexpected modifications of system or application binaries, particularly signed executables. Correlates file write events with subsequent unsigned or anomalously signed process execution, and checks for tampered binaries outside normal patch cycles.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Security EventCode=4688
[MonitoredPaths] Define critical directories (e.g., C:\Windows\System32, Program Files) for binary integrity checks
[SignatureValidation] Adjust enforcement level of digital signature verification based on enterprise risk appetite
[TimeWindow] Correlate file modification with subsequent process execution within a defined time window
AN0950 Analytic 0950
Linux

Detects modification of system or application binaries by monitoring /usr/bin, /bin, and other privileged directories. Correlates file integrity monitoring (FIM) events with unexpected process executions or service restarts.

auditd:SYSCALL open, write auditd:EXECVE execve
[WatchedDirectories] Customize monitored directories (e.g., /usr/bin, /usr/sbin, /opt/apps) for binary tampering
[BaselineHashes] Maintain golden file hashes for integrity validation
AN0951 Analytic 0951
macOS

Monitors binary modification in /Applications and system library paths. Detects unsigned or improperly signed binaries executed after modification. Tracks Gatekeeper or notarization bypass attempts tied to modified binaries.

macos:unifiedlog binary modified or replaced macos:unifiedlog execution of modified binary without valid signature
[ApplicationPaths] Tune which application and library directories are monitored for tampering
[SignatureVerificationDepth] Define strictness of code-signing validation checks
AN0952 Analytic 0952
ESXi

Detects unauthorized modification of host binaries, modules, or services within ESXi. Correlates tampered files with subsequent unexpected service behavior or malicious module load attempts.

esxi:hostd binary or module replacement event esxi:vmkernel unexpected module load
[MonitoredModules] Define critical ESXi binaries and kernel modules requiring integrity validation
[CorrelationWindow] Adjust timing correlation between binary modification and module/service anomalies

Detected Techniques

1

Details

MITRE ID
DET0336
STIX ID
x-mitre-detection-strategy--110a934e-881a-4e42-9619-b6de30f4a39e
Analytics
4
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.