T1574 Hijack Execution Flow
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution. There are many ways an…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Winnti Pipemon Characteristicscriticalstable · windows
- APT27 - Emissary Panda Activitycriticaltest · windows
- HackTool - SharpUp PrivEsc Tool Executioncriticaltest · windows
- Winnti Malware HK University Campaigncriticaltest · windows
- Suspicious Unsigned Thor Scanner Executionhighstable · windows
- Abuse of Service Permissions to Hide Services Via Set-Servicehightest · windows
- Abuse of Service Permissions to Hide Services Via Set-Service - PShightest · windows
- Aruba Network Service Potential DLL Sideloadinghightest · windows
- Code Injection by ld.so Preloadhightest · linux
- DHCP Callout DLL Installationhightest · windows
- DHCP Server Error Failed Loading the CallOut DLLhightest · windows
- DHCP Server Loaded the CallOut DLLhightest · windows
- DLL Search Order Hijackig Via Additional Space in Pathhightest · windows
- DLL Sideloading Of ShellChromeAPI.DLLhightest · windows
- DLL Sideloading by VMware Xfer Utilityhightest · windows
- DNS Server Error Failed Loading the ServerLevelPluginDLLhightest · windows
- Diamond Sleet APT DLL Sideloading Indicatorshightest · windows
- Exploiting SetupComplete.cmd CVE-2019-1378hightest · windows
- Fax Service DLL Search Order Hijackhightest · windows
- HackTool - Powerup Write Hijack DLLhightest · windows
- Lazarus APT DLL Sideloading Activityhightest · windows
- Malicious DLL File Dropped in the Teams or OneDrive Folderhightest · windows
- Microsoft Defender Blocked from Loading Unsigned DLLhightest · windows
- Microsoft Office DLL Sideloadhightest · windows
- Modification of ld.so.preloadhightest · linux
Mostrando 25 de 67.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.