Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0504 — Detect Abuse of Dynamic Data Exchange (T1559.002)
DET0504

Detect Abuse of Dynamic Data Exchange (T1559.002)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1393 Analytic 1393
Windows

Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Security EventCode=4663, 4670, 4656
[AllowedParentChildPairs] Define legitimate parent-child relationships for Office processes to reduce false positives.
[TimeWindow] Threshold for correlating Office process creation with subsequent command execution via DDE.
[SuspiciousDLLList] Maintain allow/block list of DLLs that Office is expected to load.

Detected Techniques

1

Details

MITRE ID
DET0504
STIX ID
x-mitre-detection-strategy--3f3ebc58-fff0-4083-bc5c-ee7308026a20
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.