Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1574

T1574Hijack Execution Flow

T1574 — Hijack Execution Flow is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 11 detection use cases covering it and 5 threat-intel articles citing it.

Defense EvasionExecution
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
5Articles
12Sub-techniques
2Tactics

Sub-techniques (12)

Use cases covering this technique (11)

Windows BitDefender Submission Wizard DLL Sideloading ESCU actions · alerting P Windows Mock Trusted Directory MSC File Creation ESCU actions · alerting P Windows PowerShell Module File Created ESCU actions · hunting P Windows Rundll32 Execution With Log.DLL ESCU actions · hunting P Windows Set Custom DNS ServerLevelPlugin Via Dnscmd ESCU actions · hunting P [LLM] litellm_init.pth Python autoload persistence drop Bespoke install · alerting DSΣPDDCS [LLM] Log4j logging configuration file modified (CVE-2021-44832 JDBC Appender precondition) Bespoke weapon · hunting DSΣPDDCS [LLM] Vulnerable npm/yarn/pnpm version exposed to bin-key file overwrite (CVE-2019-16776/16777/10773) Bespoke delivery · alerting DSP [LLM] npm/yarn/pnpm planting or overwriting a binary in a system bin directory Bespoke install · hunting DSΣPCS [LLM] Bower archive extraction arbitrary file write to sensitive paths (CVE-2019-5484 / Zip Slip) Bespoke exploit · hunting DSΣPDDCS [LLM] Zip Slip: archive-handler process writes shell script / web shell outside extraction dir Bespoke install · hunting DSΣPDDCS

Articles citing this technique (5)