Defense Evasion Detection Rules | Fibratus
Detection rules for Defense Evasion (MITRE ATT&CK): process hollowing, DLL sideloading, NTDLL unhooking, direct syscalls, and other evasion techniques detected at kernel runtime.
Rules in this category
- Activation Context memory section hijacking
- Activity from unhooked NTDLL module
- AppDomain Manager injection via CLR search order hijacking
- BindFlt DLL loaded by an unusual process
- CldApi DLL loaded by an unusual process
- Clear Eventlog
- Direct disk device access
- DLL loaded via APC queue
- DLL loaded via a callback function
- DLL loaded via LdrpKernel32 overwrite
- DLL Side-Loading via a copied binary
- DLL Side-Loading via Microsoft Office dropped file
- .NET assembly loaded by unmanaged process
- Hidden registry key creation
- Image load via NTFS transaction
- Potential injection via .NET debugging
- Potential NTDLL unhooking via file mapping
- Potential operation evasion via direct syscall
- Potential process creation via shellcode
- Potential process injection via tainted memory section
- Potential shellcode execution via ETW logger thread
- Potential shellcode injection via Windows Debugging API
- Potential thread execution hijacking
- Process creation from a stomped module
- Process creation via direct syscall
- Process creation via NTFS transaction
- Process execution from hollowed memory section
- Process execution from remote memory section
- Process execution from a self-deleting binary
- Process spawned from unusual directory
- Process spawned via remote thread
- Regsvr32 scriptlet execution
- Suspicious access to the hosts file
- Suspicious activity from a reflected process
- Suspicious child spawned via reflected process
- Suspicious DLL loaded via memory section mapping
- Suspicious HTML Application script execution
- Suspicious object symbolic link creation
- Suspicious protected process execution
- Suspicious virtual path redirection via bind filter
- Suspicious Windows Defender exclusions registry modification
- Suspicious XSL script execution
- System Binary Proxy Execution via Rundll32
- Thread context manipulation from exception handler
- Thread context set from unbacked memory
- Unsigned DLL injection via remote thread
- Untrusted DLL loaded from unusual directory
- Windows Defender driver unloading
- Windows Defender protection tampering via registry