Analytics BIOC
Low
✕
A rare file path was added to the AppInit_DLLs registry value
A rare file path was added to AppInit_DLLs registry value.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Event Triggered Execution (T1546)
Detector tags: Injection Analytics
Attacker's goals:
Establish persistence and/or elevate privileges by injecting malicious content triggered by AppInit DLLs loaded into processes.
Investigative actions:
Investigate the path of the modified value. Investigate the causality actor process which initiated the activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- A rare file path was added to the AppInit_DLLs registry valueusing a manual registry tool Medium (parent: Low)
- A rare file path was added to the AppInit_DLLs registry valuewith a commonly abused path Medium (parent: Low)