MITRE ATT&CK T1574 Detection Rules | Fibratus
Fibratus detection rules mapped to MITRE ATT&CK technique T1574. Kernel-level, behavior-driven detection coverage.
Rules in this category
- AppDomain Manager injection via CLR search order hijacking
- BindFlt DLL loaded by an unusual process
- CldApi DLL loaded by an unusual process
- DLL loaded via LdrpKernel32 overwrite
- DLL Side-Loading via a copied binary
- DLL Side-Loading via Microsoft Office dropped file
- Untrusted DLL loaded from unusual directory
- Potential privilege escalation via phantom DLL hijacking
- Untrusted DLL loaded from masqueraded Windows directory