1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1574.008 Path Interception by Search Order Hijacking — Detection Rules

Detection workspace for T1574.008 Path Interception by Search Order Hijacking: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0564 Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking

AN1560 Analytic 1560

Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1574.008 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.