Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0427 — Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
DET0427

Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1195 Analytic 1195
Windows

Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations.

WinEventLog:Security EventCode=4657 WinEventLog:System EventCode=7040 WinEventLog:Sysmon EventCode=1
[MonitoredServiceKeys] Registry subkeys for critical services (ImagePath, ServiceDll, FailureCommand, Parameters).
[BaselineServiceConfig] Known good service registry configurations and paths for comparison.
[TimeWindow] Correlation interval between registry/service modifications and service execution.
[PrivilegedAccounts] Accounts permitted to modify service configurations.

Detected Techniques

1

Details

MITRE ID
DET0427
STIX ID
x-mitre-detection-strategy--a44e6677-25d9-495a-91fd-e2611dac9477
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.