Hijack Execution Flow T1574

Tactics: Stealth, Execution

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Events covered

42 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 6416A new external device was recognized by the system.
Defender-DeviceFileCertificateInfoanyFile signing certificate information
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceFileEventsFileModifiedFile modified
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceInfoanyDevice information
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceRegistryEventsRegistryValueSetRegistry value set
ESFexecProcess Execution
ESFwriteFile Write
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1307CWD
Linux-AuditdEvent ID 1309EXECVE
DHCP-ServerEvent ID 1031[EVENT_SERVER_CALLOUT_UNHANDLED_EXCEPTION] The installed server callout .dll file has caused an exception.
DHCP-ServerEvent ID 1032[EVENT_SERVER_CALLOUT_LOAD_EXCEPTION] The installed server callout .dll file has caused an exception. The .dll file couldn't be loaded.
DHCP-ServerEvent ID 1033[EVENT_SERVER_CALLOUT_LOAD_SUCCESS] The DHCP service has successfully loaded one or more callout DLLs.
DHCP-ServerEvent ID 1034[EVENT_SERVER_READ_ONLY_GROUP_ERROR] The DHCP service has failed to load one or more callout DLLs.
DNS-Server-ServiceEvent ID 150The DNS server could not load or initialize the plug-in DLL Name.
DNS-Server-ServiceEvent ID 770A DNS server plugin DLL has been loaded from location param1 on server param2.
DNS-Server-ServiceEvent ID 771The V1 plugin interface has been implemented in server level plugin DLL.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PrintServiceEvent ID 321File(s) param1 associated with printer param2 were added or updated.
PrintServiceEvent ID 354param1 initialization failed at param2.
PrintServiceEvent ID 808The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode.
Security-MitigationsEvent ID 11Process 'ProcessPath' (PID ProcessId) would have been blocked from loading the non-Microsoft-signed binary 'ImageName'.
Security-MitigationsEvent ID 12Process 'ProcessPath' (PID ProcessId) was blocked from loading the non-Microsoft-signed binary 'ImageName'.
PowerShellEvent ID 800Event ID 800
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 321 rules share fields, values, and exclusions.

Fields filtered most (136 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Image114ends_with 62, starts_with 28, eq 15, is_not_null 12, contains 11, wildcard 9, in 2, is_null 1, regex_match 1\sc.exe, /boot/*, /dev/shm/*, ?:\program files (x86)\microsoft\, \cmd.exe
EventType91eq 60, in 22, ne 9, starts_with 2exec, start, creation, ProcessRollup2, rename
ImageLoaded87ends_with 59, starts_with 41, contains 19, wildcard 10, eq 9, in 2c:\program files (x86)\, c:\program files (x86)\windows kits\, c:\program files\, c:\windows\system32\, :\program files (x86)\windows kits\10\bin\
host.os.type73eq 72, in 1
process_name66eq 46, in 16, starts_with 4, wildcard 3, is_not_null 2, cross_field_compare 1, ne 1bash, csh, dash, dllhost.exe, awk
event.type65eq 59, in 3, ne 3start, creation, change, deletion, process_started
TargetFilename54wildcard 25, starts_with 10, contains 7, ends_with 6, in 6, eq 3, is_not_null 1, match 1, regex_match 1/etc/ld.so.preload, .dll, /*gconv_path*, /boot/efi/efi/*/grub.cfg, /boot/grub/grub.cfg
CommandLine37contains 33, ends_with 3, starts_with 2, eq 1, is_null 1, match 1, regex_match 1, wildcard 1config, /config, /serverlevelplugindll, dclcwpdtsd, msdtc
parent_process_name32eq 22, in 8, is_not_null 2, ends_with 1, starts_with 1bash, csh, dash, apt, cmd.exe
process.args26eq 16, in 8, starts_with 8, wildcard 6, contains 3-c, --install, -D, -i, .git/hooks/
dll.Ext.relative_file_creation_time22le 15, lt 7500, 5000, 3600, 86400, 900
OriginalFileName19eq 18, in 1, is_not_null 1, is_null 1sc.exe, -, addinprocess.exe, addinprocess32.exe, addinutil.exe
dll.Ext.relative_file_name_modify_time18le 12, lt 6500, 5000, 3600, 172800, 900
SignatureStatus17eq 14, ne 3valid, trusted, unavailable, Valid, expired
Signed16eq 16true, false

Top indicator values (5356 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
451078
event.typeeq
creation
953
EventTypeeq
exec
23576
EventTypeeq
start
20391
EventTypeeq
connection_attempted
773
EventTypein
exec
13201
EventTypein
start
12163
EventTypein
ProcessRollup2
11117
EventTypein
exec_event
8149
EventIDeq
7
1141
Signedeq
true
102
process_namein
bash
10202
process_namein
csh
10159
process_namein
dash
10170
process_namein
fish
10163
process_namein
ksh
10163
process_namein
sh
10197
process_namein
tcsh
10156
process_namein
zsh
10196
ImageLoadedstarts_with
c:\windows\system32\
9
ImageLoadedstarts_with
c:\windows\syswow64\
9
ImageLoadedstarts_with
c:\windows\winsxs\
9
ImageLoadedstarts_with
c:\program files (x86)\
8
ImageLoadedstarts_with
c:\program files\
8
event.categoryeq
process
9142
EventTypene
deletion
886
file.Ext.header_bytesstarts_with
4d5a
846
process.Ext.token.integrity_level_nameeq
high
822
process.code_signature.trustedeq
true
814
process_nameeq
dllhost.exe
819

Exclusions (2268 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
14
dll.code_signature.statuswildcard
errorCode_endpoint*
13
dll.code_signature.statuswildcard
trusted
12
Imagein
/usr/bin/dockerd
12
Imagein
/usr/bin/podman
12
Imagein
./usr/bin/podman
11
Imagein
/bin/podman
11
Imagein
/usr/bin/dnf
11
Imagein
/usr/sbin/dockerd
11
Imagein
/bin/dnf
10
Imagein
/bin/dnf-automatic
10
Imagein
/bin/dockerd
10
Imagein
/bin/microdnf
10
Imagein
/bin/rpm
10
Imagein
/bin/snapd
10

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 134 rules

Elastic 148 rules

Splunk 33 rules

Kusto 6 rules