AN0277
Analytic 0277
Windows
Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.
WinEventLog:Sysmon
EventCode=10
WinEventLog:Sysmon
EventCode=8
etw:Microsoft-Windows-Kernel-Process
APCQueueOperations
WinEventLog:Sysmon
EventCode=1
[APCTargetProcessList]
Processes that are rarely or never valid targets for legitimate APC queuing (e.g., lsass.exe, winlogon.exe)
[ThreadQueueDepthThreshold]
The number of APCs queued within a short time window that could signal abuse
[TimeWindow]
Expected latency between memory allocation and thread execution through APC
[UserContextSensitivity]
Used to filter based on expected vs unexpected user to target process pairings