Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0595 — Detection Strategy for Exploitation for Stealth
DET0595

Detection Strategy for Exploitation for Stealth

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1633 Analytic 1633
Windows

Detects exploitation attempts targeting defensive security software or OS services. Defender observation includes abnormal process behavior (e.g., AV or EDR crashing unexpectedly), unsigned/untrusted modules loaded into defensive processes, or privilege escalation from security agent services. Multi-event correlation ties exploitation attempts to subsequent evasive behavior like service termination or missing logs.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7
[DefensiveProcessList] List of defensive services/processes (e.g., AV, EDR) monitored in the environment.
[AllowedModulePaths] Whitelisted DLL/module paths normally loaded by defensive tools.
[CrashThreshold] Number of abnormal terminations of defensive processes tolerated before triggering an alert.
AN1634 Analytic 1634
Linux

Detects kernel- or user-space exploitation attempts targeting auditd, AV daemons, or security monitoring agents. Defender observation includes unexpected segfaults, privilege escalation attempts from low-privileged processes, or modifications to security binaries. Correlates exploitation attempts with subsequent gaps in logging or terminated processes.

auditd:SYSCALL execve: Execution of suspicious exploit binaries targeting security daemons linux:syslog Segfaults, kernel oops, or crashes in security software processes
[WatchedBinaries] List of critical security daemons (e.g., auditd, falco, AV agents) to monitor for exploitation.
[CrashPatterns] Regex or patterns for kernel/syslog errors correlated with exploitation attempts.
AN1635 Analytic 1635
macOS

Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs.

macos:unifiedlog Abnormal terminations of com.apple.security.* or 3rd-party security daemons macos:osquery execve: Unsigned or unnotarized processes launched with high privileges
[SecurityDaemons] Monitored Apple and third-party EDR/AV daemon names.
[UnsignedProcessThreshold] Number of unsigned high-privilege executions before alerting.
AN1636 Analytic 1636
IaaS

Detects exploitation of IaaS cloud security boundaries to evade defense controls. Defender perspective includes anomalous API calls that bypass audit logging, disable monitoring, or manipulate guardrails (e.g., CloudTrail tampering). Correlation highlights when exploitation attempts precede sudden absence of expected telemetry.

AWS:CloudTrail StopLogging, DeleteTrail, UpdateTrail: API calls that disable or modify logging services
[CriticalAPIs] List of sensitive cloud API operations that should be rare and tightly monitored.
[TimeWindow] Duration for correlation of API exploitation with sudden logging gaps.
AN1637 Analytic 1637
SaaS

Detects adversary abuse of SaaS platform vulnerabilities to bypass logging, monitoring, or consent boundaries. Defender perspective focuses on abnormal application integration events, missing audit logs, or API calls from unauthorized service principals that align with exploitation attempts.

m365:unified ApplicationModified, ConsentGranted: Unexpected app consent or modification events linked to security evasion
[MonitoredApps] Applications and integrations expected in the environment; deviations may be suspect.
[ConsentAnomalyThreshold] Threshold for anomalous OAuth or app consent events before flagging exploitation.

Detected Techniques

1

Details

MITRE ID
DET0595
STIX ID
x-mitre-detection-strategy--da1e3af8-d79b-44ff-a907-ae107c110671
Analytics
5
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.