Analytics BIOC Low

Image file execution options (IFEO) registry key set

Attackers may use the Image File Execution Options Registry key to launch their executable whenever the user attempts to execute a certain executable.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Event Triggered Execution: Image File Execution Options Injection (T1546.012)
Attacker's goals:

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options debuggers.

Investigative actions:

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Look at the debugged process and what it is executing to determine if it is malicious.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Image file execution options (IFEO) registry key set to execute a shell or scripting engine process High (parent: Low)
  • Image file execution options (IFEO) registry key set to activate Windows licenses illegally Medium (parent: Low)
  • Image file execution options (IFEO) registry key set using reg.exe High (parent: Low)