Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0091 — Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups
DET0091

Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0250 Analytic 0250
Windows

Behavioral chain involving suspicious use of GetProcAddress and LoadLibrary following memory allocation and manual mapping, often paired with low entropy strings, abnormal API use without static import tables, or delayed module load behaviors.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 etw:Microsoft-Windows-Kernel-Process API tracing / stack tracing via ETW or telemetry-based EDR
[APILoadWithoutImport] Tunable logic to flag suspicious modules used without static IAT entries
[TimeWindow] Correlates module load to suspicious memory allocation or API lookup within timeframe
[EntropyThreshold] Used to detect obfuscated strings or hashed function names
[StackTraceFilter] Optional filtering of known safe modules or patterns from telemetry

Detected Techniques

1

Details

MITRE ID
DET0091
STIX ID
x-mitre-detection-strategy--063eac3f-9c2a-429a-ad7c-ae7f49158bb2
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.