{"id":"T1055.005","name":"Thread Local Storage","url":"https://attack.mitre.org/techniques/T1055/005","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0467","stix_id":"x-mitre-detection-strategy--a14db1ea-e57e-4bc4-83bb-94a6e7da87b0","name":"Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing","url":"https://attack.mitre.org/detectionstrategies/DET0467","analytics":[{"id":"AN1289","stix_id":"x-mitre-analytic--44500eb7-01f2-4cab-8b76-1227bb48e13e","name":"Analytic 1289","description":"Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution.","url":"https://attack.mitre.org/detectionstrategies/DET0467#AN1289","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:memory","channel":"MemoryWriteToExecutable","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"edr-memory"}],"mutable_elements":[{"field":"TargetProcessFilter","description":"Subset of processes whose TLS callbacks should not change post-load (e.g., explorer.exe, lsass.exe)"},{"field":"TimeWindowBetweenLoadAndTLSModification","description":"Acceptable delay between image load and memory tampering in .tls or .data sections"},{"field":"AnomalousThreadStartThreshold","description":"Number of threads executing prior to main entry point that is considered suspicious"},{"field":"PayloadEntropyThreshold","description":"Optional threshold to distinguish injected shellcode from benign memory writes"}],"live":true,"detection_strategies":["DET0467"],"techniques":["T1055.005"]}],"live":true,"version":"1.0","techniques":["T1055.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}