kevmap

TechniquesT1546 › AN0024

AN0024 Analytic 0024

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.</p>
Detects
T1546 Event Triggered Execution
Part of
DET0010 Behavioral Detection of Event Triggered Execution Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4698DC0001 Scheduled Job Creation
WinEventLog:WMICreation or modification of __EventFilter, __FilterToConsumerBinding, or CommandLineEventConsumerDC0008 WMI Creation
WinEventLog:SecurityEventCode=4657DC0063 Windows Registry Key Modification
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserContextFilters triggering on SYSTEM or LOCAL SERVICE vs. user-initiated triggers
TimeWindowCorrelates trigger definition and execution timing (e.g., within 5 minutes)
PathAnomalyThresholdProcess or binary path deviation scoring for execution anomalies