AN1501
Analytic 1501
Windows
Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=10
WinEventLog:Sysmon
EventCode=11
etw:Microsoft-Windows-Kernel-Process
CreateTransaction, CreateFileTransacted, RollbackTransaction, NtCreateProcessEx, NtCreateThreadEx
[TransactionExecutableNamePattern]
Pattern of legitimate executables often used as doppelgänging targets (e.g., svchost.exe, calc.exe)
[TimeWindow_TransactionToExecution]
Time delta between TxF rollback and thread creation in hollowed process
[ThreadStartEntropyThreshold]
Entropy level of thread start address in memory used to detect obfuscated shellcode
[TxF API Call Frequency Threshold]
Limit on CreateTransaction + RollbackTransaction sequences per process