{"id":"T1574.013","name":"KernelCallbackTable","url":"https://attack.mitre.org/techniques/T1574/013","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0577","stix_id":"x-mitre-detection-strategy--7ee8426e-2b65-44ed-b6d4-3800b92adf2e","name":"Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.","url":"https://attack.mitre.org/detectionstrategies/DET0577","analytics":[{"id":"AN1593","stix_id":"x-mitre-analytic--da853af7-f2e4-45c2-b78f-3d960fff638e","name":"Analytic 1593","description":"Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.","url":"https://attack.mitre.org/detectionstrategies/DET0577#AN1593","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"WriteProcessMemory: WriteProcessMemory targeting regions containing KernelCallbackTable addresses","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"}],"mutable_elements":[{"field":"MonitoredProcesses","description":"GUI applications (e.g., explorer.exe, notepad.exe) where KernelCallbackTable abuse is more likely."},{"field":"CallbackFunctions","description":"Specific callback functions (e.g., fnCOPYDATA, fnDWORD) expected to remain stable."},{"field":"TimeWindow","description":"Correlation interval between WriteProcessMemory calls and execution of modified callback functions."},{"field":"AccessMaskThresholds","description":"Access rights values that should be flagged when targeting GUI processes."}],"live":true,"detection_strategies":["DET0577"],"techniques":["T1574.013"]}],"live":true,"version":"1.0","techniques":["T1574.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}