Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0217 — Detection Strategy for Extra Window Memory (EWM) Injection on Windows
DET0217

Detection Strategy for Extra Window Memory (EWM) Injection on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0608 Analytic 0608
Windows

Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.

WinEventLog:Sysmon EventCode=10 etw:Microsoft-Windows-Win32k SetWindowLong, SetClassLong, NtUserMessageCall, SendNotifyMessage, PostMessage WinEventLog:Security EventCode=4688
[TargetWindowClassRegex] Regex to scope suspicious or uncommon GUI class names registered by user-created processes
[ExecutionTriggerWindowMessage] API calls like SendNotifyMessage or PostMessage that deliver execution to the shellcode location
[SharedSectionWriteThreshold] Set byte count thresholds on suspicious memory writes to known shared sections
[TimeWindowSetWindowLongToMessageTrigger] Define max time (e.g., <10s) between API call to set window memory and the message call to trigger it

Detected Techniques

1

Details

MITRE ID
DET0217
STIX ID
x-mitre-detection-strategy--1a8d87f1-48ca-4929-a5cc-2b2a03983f12
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.