Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0575 — Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)
DET0575

Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1588 Analytic 1588
Windows

Detection focuses on monitoring registry modifications under HKLM\SOFTWARE\Microsoft\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[TimeWindow] Defines the time window in which correlated registry and execution events are considered suspicious (e.g., within 10 minutes)
[NetshChildProcessWhitelist] List of expected or approved child processes spawned by netsh.exe in the enterprise environment
[DLLLoadPath] Directory or filename heuristics to distinguish benign DLLs from malicious helper DLLs

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0575
STIX ID
x-mitre-detection-strategy--8d407bff-f721-4b74-a593-1e55c14c5263
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.