MITRE ATT&CK T1055 Detection Rules | Fibratus
Reglas de detección de Fibratus mapeadas a la técnica T1055 de MITRE ATT&CK. Cobertura basada en comportamiento a nivel de kernel.
Reglas en esta categoría
- Activation Context memory section hijacking
- Activity from unhooked NTDLL module
- DLL loaded via APC queue
- DLL loaded via a callback function
- .NET assembly loaded by unmanaged process
- Image load via NTFS transaction
- Potential injection via .NET debugging
- Potential NTDLL unhooking via file mapping
- Potential operation evasion via direct syscall
- Potential process creation via shellcode
- Potential process injection via tainted memory section
- Potential shellcode execution via ETW logger thread
- Potential shellcode injection via Windows Debugging API
- Potential thread execution hijacking
- Process creation from a stomped module
- Process creation via direct syscall
- Process creation via NTFS transaction
- Process execution from hollowed memory section
- Process execution from remote memory section
- Process execution from a self-deleting binary
- Process spawned via remote thread
- Suspicious activity from a reflected process
- Suspicious child spawned via reflected process
- Suspicious DLL loaded via memory section mapping
- Thread context manipulation from exception handler
- Thread context set from unbacked memory
- Unsigned DLL injection via remote thread