Analytics BIOC Low

A rare file path was added to the AppInit_DLLs registry value

A rare file path was added to AppInit_DLLs registry value.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution (T1546)
Detector tags: Injection Analytics
Attacker's goals:

Establish persistence and/or elevate privileges by injecting malicious content triggered by AppInit DLLs loaded into processes.

Investigative actions:

Investigate the path of the modified value. Investigate the causality actor process which initiated the activity.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A rare file path was added to the AppInit_DLLs registry valueusing a manual registry tool Medium (parent: Low)
  • A rare file path was added to the AppInit_DLLs registry valuewith a commonly abused path Medium (parent: Low)