T1106 Native API
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Turla Group Named Pipescriticaltest · windows
- BPFDoor Abnormal Process ID or Lock File Accessedhightest · linux
- HackTool - CobaltStrike BOF Injection Patternhightest · windows
- HackTool - HandleKatz Duplicating LSASS Handlehightest · windows
- HackTool - RedMimicry Winnti Playbook Executionhightest · windows
- HackTool - WinPwn Executionhightest · windows
- HackTool - WinPwn Execution - ScriptBlockhightest · windows
- Potential WinAPI Calls Via CommandLinehightest · windows
- Potential WinAPI Calls Via PowerShell Scriptshightest · windows
- Suspicious Mshta.EXE Execution Patternshightest · windows
- Potential Binary Proxy Execution Via Cdb.EXEmediumtest · windows
- Potential Direct Syscall of NtOpenProcessmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.