Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0450 — Detection Strategy for Kernel Modules and Extensions Autostart Execution
DET0450

Detection Strategy for Kernel Modules and Extensions Autostart Execution

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1243 Analytic 1243
Linux

Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users.

auditd:SYSCALL Execution of insmod, modprobe, or rmmod commands by non-standard users or outside expected timeframes auditd:SYSCALL Access or modification to /lib/modules or creation of .ko files linux:osquery New or modified kernel object files (.ko) within /lib/modules directory
[UserContext] Scope detection to non-root or unexpected users performing module-related activity
[TimeWindow] Limit alerts to module activity outside approved change windows
[FilePathRegex] Adjust regex pattern for directories to monitor depending on kernel version or distro
AN1244 Analytic 1244
macOS

Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources.

macos:unifiedlog kextload execution from Terminal or suspicious paths macos:osquery Processes executing kextload, spctl, or modifying kernel extension directories macos:osquery New kext entries not signed by Apple or outside standard identifier prefix macos:osquery Modifications to /var/db/SystemPolicyConfiguration/KextPolicy or kext_policy table
[DeveloperIDAllowlist] Approved developer IDs whose kexts should not trigger alerts
[KextLoadTimeWindow] Threshold for detecting kext loads outside standard install/update operations
[SignatureCheckFlag] Flag to enforce strict signing checks depending on SIP status

Detected Techniques

1

Details

MITRE ID
DET0450
STIX ID
x-mitre-detection-strategy--df1da8e4-cabf-42f0-8f5f-2fa8086b1423
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.