1200KM / detection
T1574 Hijack Execution Flow — Detection Rules
Detection workspace for T1574 Hijack Execution Flow: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Initial Access via DLL Search Order Hijacking · test · medium · {"product":"windows","category":"file_event"}
- DLL Execution Via Register-cimprovider.exe · test · medium · {"category":"process_creation","product":"windows"}
- Regsvr32 DLL Execution With Uncommon Extension · test · medium · {"category":"process_creation","product":"windows"}
- Potential Registry Persistence Attempt Via DbgManagedDebugger · test · medium · {"category":"registry_set","product":"windows"}
- Suspicious Printer Driver Empty Manufacturer · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0218 Detection Strategy for Hijack Execution Flow across OS platforms.
AN0609 Analytic 0609
Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths.
AN0610 Analytic 0610
Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables.
AN0611 Analytic 0611
Abuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Creation · DC0039
- File Modification · DC0061
- Module Load · DC0016
- Process Creation · DC0032
- Service Metadata · DC0041
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.