Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0122 — Detect Abuse of Windows Time Providers for Persistence
DET0122

Detect Abuse of Windows Time Providers for Persistence

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0341 Analytic 0341
Windows

Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.

WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=1
[RegistryPathScope] May need to be tuned to only monitor `W32Time\TimeProviders` subkey path for performance optimization
[UserContext] Should focus on activity from administrative or SYSTEM accounts
[TimeWindow] Controls correlation window between registry modification and DLL drop
[DllPathEntropyThreshold] Used for anomaly scoring on DLL path patterns (e.g., random names or temp directories)

Detected Techniques

1

Details

MITRE ID
DET0122
STIX ID
x-mitre-detection-strategy--9c4b0b07-df7f-4697-8cd1-0b95ff6a6361
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.