Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0295 — Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching
DET0295

Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0822 Analytic 0822
Windows

Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread).

WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=8 etw:Microsoft-Windows-Kernel-Process API Calls WinEventLog:Sysmon EventCode=1
[TargetProcessList] Sensitive processes that should never be targeted for thread hijack attempts
[TimeWindow] Expected delay between SuspendThread and ResumeThread events; tight thresholds reduce evasion
[SuspiciousThreadContextRegions] Memory regions or offsets that should not be targeted for SetThreadContext
[ParentProcessAnomalyThreshold] Score deviation of the parent/child relationship in a thread injection chain

Detected Techniques

1

Details

MITRE ID
DET0295
STIX ID
x-mitre-detection-strategy--47dd679b-1bd4-4bb7-a946-5d77fd49a939
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.