Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0422 — Detection Strategy for IFEO Injection on Windows
DET0422

Detection Strategy for IFEO Injection on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1186 Analytic 1186
Windows

Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=12
[TimeWindow] Time delta for correlating registry modification and debugger-triggered execution
[TargetBinary] Specific executables that trigger defenders’ alerts when IFEO values are set
[ParentProcessAnomaly] Tunable logic for detecting parent-child anomalies (e.g., non-standard parent processes)
[TokenElevationContext] May require tuning based on normal SYSTEM or admin process elevation patterns

Detected Techniques

1

Details

MITRE ID
DET0422
STIX ID
x-mitre-detection-strategy--d65ea5cc-52c6-4ec6-98a8-eef0be23ee72
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.