// MITRE ATT&CK

T1574.009 · Path Interception by Unquoted Path

🎯 Stealth Windows Sub-técnica

Sub-técnica de T1574 · Hijack Execution Flow.

Adversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can take advantage of paths that lack surrounding quotations by placing an executable in a higher level directory within the path, so that Windows will choose the adversary's executable to ...

¿Cómo detectarlo y mitigarlo?

La detección de Path Interception by Unquoted Path parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.