Image file execution options (IFEO) registry key set
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Event Triggered Execution: Image File Execution Options Injection (T1546.012)
Severity
Low
Description
Attackers may use the Image File Execution Options Registry key to launch their executable whenever the user attempts to execute a certain executable.
Attacker's Goals
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options debuggers.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Look at the debugged process and what it is executing to determine if it is malicious.
Variations
Was this helpful?
