kevmap

TechniquesT1574 › AN0609

AN0609 Analytic 0609

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths.</p>
Detects
T1574 Hijack Execution Flow
Part of
DET0218 Detection Strategy for Hijack Execution Flow across OS platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=7DC0016 Module Load
WinEventLog:SecurityEventCode=4657DC0063 Windows Registry Key Modification
WinEventLog:SysmonEventCode=11DC0039 File Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ServiceBaselineExpected registry keys and service paths for comparison.
AllowedDllPathsDirectories considered valid for DLL loading.
TimeWindowCorrelation interval between registry/file modification and process execution.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2016-1010Adobe Flash Player and AIRMapped
CVE-2017-6742Cisco IOS and IOS XE SoftwareMapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR)Mapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-3038Google Chromium Network ServiceMapped
CVE-2022-41073Microsoft WindowsMapped
CVE-2022-41328Fortinet FortiOSMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNMapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-5217Google Chromium libvpxMapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-21762Fortinet FortiOSMapped
CVE-2025-27363FreeType FreeTypeMapped