T1055.001 Dynamic-link Library Injection
Subtécnica de T1055 Process Injection
Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges. DLL injection is a method of executing arbitrary code in the address space of a separate live process. DLL injection is commonly performed by writing the path to a DLL in the virtual address space of the target process before loading the DLL by…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - Potential CobaltStrike Process Injectionhightest · windows
- ManageEngine Endpoint Central Dctask64.EXE Potential Abusehightest · windows
- Mavinject Inject DLL Into Running Processhightest · windows
- Renamed Mavinject.EXE Executionhightest · windows
- Renamed ZOHO Dctask64 Executionhightest · windows
- TAIDOOR RAT DLL Loadhightest · windows
- Potential DLL Injection Or Execution Using Tracker.exemediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.