Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0564 — Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking
DET0564

Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1560 Analytic 1560
Windows

Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=15 WinEventLog:Sysmon EventCode=1
[SuspiciousBinaryList] Common system utilities often hijacked (e.g., net.exe, cmd.exe, powershell.exe, python.exe).
[MonitoredDirectories] Directories where executables should not normally be written (e.g., application folders, user profile subdirs).
[TimeWindow] Correlation window between file creation and subsequent process execution.
[ParentProcessBaseline] Expected parent processes for critical system binaries, deviations may indicate hijacking.

Details

MITRE ID
DET0564
STIX ID
x-mitre-detection-strategy--9050bfb8-840d-4464-b4e8-7a0dbdece715
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.