Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0436 — Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.
DET0436

Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1211 Analytic 1211
Windows

Modification or replacement of service executables due to weak file or directory permissions. Defender observes file writes to service binary paths, unexpected modifications of executables associated with registered services, and subsequent service execution of attacker-supplied binaries under elevated permissions.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=15 WinEventLog:System EventCode=7045 WinEventLog:Sysmon EventCode=1
[MonitoredServices] List of critical services and their expected executable paths for integrity checking.
[HashBaseline] Baseline hashes of legitimate service executables for tamper detection.
[TimeWindow] Correlation interval between file modification of service executables and service execution.
[PrivilegedAccounts] Accounts allowed to legitimately modify service executables.

Detected Techniques

1

Details

MITRE ID
DET0436
STIX ID
x-mitre-detection-strategy--7e71997a-80b5-4d0d-807e-472116b46b77
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.