Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0479 — Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.
DET0479

Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1319 Analytic 1319
Windows

Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11
[AllowedProfilers] List of known good COR_PROFILER CLSIDs and DLLs expected in developer or monitoring environments.
[ProcessScope] Processes expected to load COR_PROFILER (e.g., Visual Studio) for baseline comparison.
[TimeWindow] Interval between registry modification or file creation and profiler DLL load into .NET processes.
[ProfilerDllPaths] Directories considered legitimate for profiler DLLs; deviations should raise alerts.

Detected Techniques

1

Details

MITRE ID
DET0479
STIX ID
x-mitre-detection-strategy--8276f61b-0147-4e72-94fb-7cdd47dc60ec
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.