Hijack Execution Flow: KernelCallbackTable T1574.013
Tactics: Stealth, Execution
Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own payloads. The KernelCallbackTable can be found in the Process Environment Block (PEB) and is initialized to an array of graphic functions available to a GUI process once user32.dll is loaded.
Authoring guide
These 2 rules share fields, values, and exclusions.
Fields filtered most (7 distinct)
These fields appear most often in rule filters.
Top indicator values (14 distinct)
These values appear most often in rule predicates.
Exclusions (53 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint