Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0152 — Detection Strategy for Hijack Execution Flow: Dylib Hijacking
DET0152

Detection Strategy for Hijack Execution Flow: Dylib Hijacking

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0435 Analytic 0435
macOS

Detection focuses on adversaries placing or modifying malicious dylibs in locations searched by legitimate applications. From the defender’s perspective, observable patterns include unexpected creation or modification of dylib files in application bundle paths, unusual module loads by processes compared to historical baselines, and execution of applications loading dylibs from suspicious directories (e.g., /tmp, user-controlled paths). Correlation across file system changes, process execution, and module loads provides high-fidelity detection.

macos:unifiedlog process execution events with dylib load activity macos:unifiedlog create/modify dylib files in monitored directories macos:unifiedlog replace existing dylibs
[MonitoredDirectories] Application bundle directories (e.g., /Applications/*/Contents/MacOS, /Library/Frameworks). Adversaries may use non-standard paths like /tmp.
[BaselineDylibs] Historical record of dylibs typically loaded by applications. Deviations should be flagged.
[CorrelationWindow] Timeframe to correlate dylib file modification with subsequent process execution and module loads.

Detected Techniques

1

Details

MITRE ID
DET0152
STIX ID
x-mitre-detection-strategy--eca47fcc-6bee-43b1-9569-631a22be5fe0
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.