Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0557 — Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)
DET0557

Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1536 Analytic 1536
Windows

Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=13, 14
[ImagePathWhitelist] Paths or filenames of known-good DLLs to exclude from alerting
[UserContext] Context of the user modifying the registry key (e.g., admin vs standard user)
[TimeWindow] Temporal threshold for correlating registry modification and DLL load
[DLLSignatureStatus] Filter or flag unsigned or suspiciously signed DLLs

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0557
STIX ID
x-mitre-detection-strategy--6f59bdfc-8352-4e6f-bef1-cc59b4e9b04d
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.