Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0100 — Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing
DET0100

Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0277 Analytic 0277
Windows

Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=8 etw:Microsoft-Windows-Kernel-Process APCQueueOperations WinEventLog:Sysmon EventCode=1
[APCTargetProcessList] Processes that are rarely or never valid targets for legitimate APC queuing (e.g., lsass.exe, winlogon.exe)
[ThreadQueueDepthThreshold] The number of APCs queued within a short time window that could signal abuse
[TimeWindow] Expected latency between memory allocation and thread execution through APC
[UserContextSensitivity] Used to filter based on expected vs unexpected user to target process pairings

Detected Techniques

1

Details

MITRE ID
DET0100
STIX ID
x-mitre-detection-strategy--4554ad15-dc0a-44f8-92b6-b8e7dc64385e
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.