// MITRE ATT&CK
T1574 · Hijack Execution Flow
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade def...
How to detect & mitigate it
Detecting Hijack Execution Flow starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (12)
T1574.001
DLL T1574.004
Dylib Hijacking T1574.005
Executable Installer File Permissions Weakness T1574.006
Dynamic Linker Hijacking T1574.007
Path Interception by PATH Environment Variable T1574.008
Path Interception by Search Order Hijacking T1574.009
Path Interception by Unquoted Path T1574.010
Services File Permissions Weakness T1574.011
Services Registry Permissions Weakness T1574.012
COR_PROFILER T1574.013
KernelCallbackTable T1574.014
AppDomainManager
DLL T1574.004
Dylib Hijacking T1574.005
Executable Installer File Permissions Weakness T1574.006
Dynamic Linker Hijacking T1574.007
Path Interception by PATH Environment Variable T1574.008
Path Interception by Search Order Hijacking T1574.009
Path Interception by Unquoted Path T1574.010
Services File Permissions Weakness T1574.011
Services Registry Permissions Weakness T1574.012
COR_PROFILER T1574.013
KernelCallbackTable T1574.014
AppDomainManager
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.