// MITRE ATT&CK

T1574.008 · Path Interception by Search Order Hijacking

🎯 Stealth Windows Sub-técnica

Sub-técnica de T1574 · Hijack Execution Flow.

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating syst...

¿Cómo detectarlo y mitigarlo?

La detección de Path Interception by Search Order Hijacking parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.