1200KM / detection
T1574.006 Dynamic Linker Hijacking — Detection Rules
Detection workspace for T1574.006 Dynamic Linker Hijacking: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Modification of ld.so.preload · test · high · {"product":"linux","service":"auditd"}
- Code Injection by ld.so Preload · test · high · {"product":"linux"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0435 Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking
AN1209 Analytic 1209
Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior.
AN1210 Analytic 1210
Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1574.006 simulation workspace
- File Creation · DC0039
- File Modification · DC0061
- Module Load · DC0016
- Process Creation · DC0032
- Process Metadata · DC0034
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.