Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0362 — Detection Strategy for AppCert DLLs Persistence via Registry Injection
DET0362

Detection Strategy for AppCert DLLs Persistence via Registry Injection

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1029 Analytic 1029
Windows

Detection of AppCert DLL abuse involves correlating registry modifications to the AppCertDLLs key with subsequent unexpected DLL load behavior during process creation events. Specifically, defenders can observe abnormal DLLs being loaded into standard Windows processes after changes to the 'AppCertDLLs' registry value. Monitoring CreateProcess-family API executions with injected DLLs and linking those DLLs back to recent registry edits is key to identifying misuse. This is often accompanied by elevated privileges and potential lateral movement or discovery behavior.

WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[TargetObject] Registry path for AppCertDLLs may vary by control set or group policy context
[ImageLoaded] Loaded DLLs may differ by malware family or environment
[ParentImage] Parent processes to monitor for DLL injection can be tuned to exclude known-good cases
[TimeWindow] Time correlation between registry modification and DLL load events may vary

Detected Techniques

1

Privilege Escalation (1)

Details

MITRE ID
DET0362
STIX ID
x-mitre-detection-strategy--3de93376-739e-4842-875d-d6e9948db8d4
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.