{"id":"T1055.004","name":"Asynchronous Procedure Call","url":"https://attack.mitre.org/techniques/T1055/004","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0100","stix_id":"x-mitre-detection-strategy--4554ad15-dc0a-44f8-92b6-b8e7dc64385e","name":"Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing","url":"https://attack.mitre.org/detectionstrategies/DET0100","analytics":[{"id":"AN0277","stix_id":"x-mitre-analytic--f0fce510-b195-4688-a4ac-b78584febd08","name":"Analytic 0277","description":"Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.","url":"https://attack.mitre.org/detectionstrategies/DET0100#AN0277","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"APCQueueOperations","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"APCTargetProcessList","description":"Processes that are rarely or never valid targets for legitimate APC queuing (e.g., lsass.exe, winlogon.exe)"},{"field":"ThreadQueueDepthThreshold","description":"The number of APCs queued within a short time window that could signal abuse"},{"field":"TimeWindow","description":"Expected latency between memory allocation and thread execution through APC"},{"field":"UserContextSensitivity","description":"Used to filter based on expected vs unexpected user to target process pairings"}],"live":true,"detection_strategies":["DET0100"],"techniques":["T1055.004"]}],"live":true,"version":"1.0","techniques":["T1055.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}