1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1574.009 Path Interception by Unquoted Path — Detection Rules

Detection workspace for T1574.009 Path Interception by Unquoted Path: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0064 Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path

AN0176 Analytic 0176

Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1574.009 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.