Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0064 — Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path
DET0064

Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0176 Analytic 0176
Windows

Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=15
[MonitoredServices] List of critical services to check for unquoted paths in ImagePath registry keys.
[SuspiciousBinaryList] Executables with names matching potential interception targets (e.g., program.exe, net.exe).
[TimeWindow] Correlation interval between file creation in parent directories and execution of unquoted path process.
[BaselineServiceConfig] Known good service paths for comparison against modified or unquoted values.

Detected Techniques

1

Details

MITRE ID
DET0064
STIX ID
x-mitre-detection-strategy--26a281d7-c49e-4e36-ab51-26a757559cf0
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.