Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0544 — Detection Strategy for Process Doppelgänging on Windows
DET0544

Detection Strategy for Process Doppelgänging on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1501 Analytic 1501
Windows

Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=11 etw:Microsoft-Windows-Kernel-Process CreateTransaction, CreateFileTransacted, RollbackTransaction, NtCreateProcessEx, NtCreateThreadEx
[TransactionExecutableNamePattern] Pattern of legitimate executables often used as doppelgänging targets (e.g., svchost.exe, calc.exe)
[TimeWindow_TransactionToExecution] Time delta between TxF rollback and thread creation in hollowed process
[ThreadStartEntropyThreshold] Entropy level of thread start address in memory used to detect obfuscated shellcode
[TxF API Call Frequency Threshold] Limit on CreateTransaction + RollbackTransaction sequences per process

Detected Techniques

1

Details

MITRE ID
DET0544
STIX ID
x-mitre-detection-strategy--8373cca7-feb8-44e4-94d0-fc39ea3586d7
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.