Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0068 — Detection Strategy for T1505.004 - Malicious IIS Components
DET0068

Detection Strategy for T1505.004 - Malicious IIS Components

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0184 Analytic 0184
Windows

Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=1 WinEventLog:System Changes to applicationhost.config or DLLs loaded by w3wp.exe WinEventLog:Microsoft-IIS-Configuration Module or ISAPI filter registration events
[TimeWindow] Adjustable time frame for detecting chained events (e.g., config change + module load)
[UserContext] Scope detection to specific users or roles allowed to modify IIS components
[WatchedPaths] Specific directories such as %windir%\System32\inetsrv\ for DLL monitoring
[DLLNameEntropyThreshold] Entropy or name patterns to flag suspicious DLLs registered as components
[ParentProcessName] Restrict to DLLs loaded by w3wp.exe or invoked via AppCmd.exe

Detected Techniques

1

Details

MITRE ID
DET0068
STIX ID
x-mitre-detection-strategy--32af4177-8c33-43d8-8e2c-9e11ac6dd451
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.