Analytics BIOC
Low
✕
Image file execution options (IFEO) registry key set
Attackers may use the Image File Execution Options Registry key to launch their executable whenever the user attempts to execute a certain executable.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Event Triggered Execution: Image File Execution Options Injection (T1546.012)
Attacker's goals:
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options debuggers.
Investigative actions:
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Look at the debugged process and what it is executing to determine if it is malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Image file execution options (IFEO) registry key set to execute a shell or scripting engine process High (parent: Low)
- Image file execution options (IFEO) registry key set to activate Windows licenses illegally Medium (parent: Low)
- Image file execution options (IFEO) registry key set using reg.exe High (parent: Low)