// MITRE ATT&CK

T1574.008 · Path Interception by Search Order Hijacking

🎯 Stealth Windows Sub-technique

Sub-technique of T1574 · Hijack Execution Flow.

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating syst...

How to detect & mitigate it

Detecting Path Interception by Search Order Hijacking starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.