A rare file path was added to the AppInit_DLLs registry value
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Injection Analytics
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Event Triggered Execution (T1546)
Severity
Low
Description
A rare file path was added to AppInit_DLLs registry value.
Attacker's Goals
Establish persistence and/or elevate privileges by injecting malicious content triggered by AppInit DLLs loaded into processes.
Investigative actions
Investigate the path of the modified value.
Investigate the causality actor process which initiated the activity.
Variations
PreviousA rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process
NextA rare FTP user has been detected on an existing FTP server
Was this helpful?
