{"id":"T1211","name":"Exploitation for Stealth","url":"https://attack.mitre.org/techniques/T1211","tactics":["stealth"],"platforms":["Linux","Windows","macOS","SaaS","IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0595","stix_id":"x-mitre-detection-strategy--da1e3af8-d79b-44ff-a907-ae107c110671","name":"Detection Strategy for Exploitation for Stealth","url":"https://attack.mitre.org/detectionstrategies/DET0595","analytics":[{"id":"AN1633","stix_id":"x-mitre-analytic--e5b0fcab-05e5-4687-a1a9-dd382a19980b","name":"Analytic 1633","description":"Detects exploitation attempts targeting defensive security software or OS services. Defender observation includes abnormal process behavior (e.g., AV or EDR crashing unexpectedly), unsigned/untrusted modules loaded into defensive processes, or privilege escalation from security agent services. Multi-event correlation ties exploitation attempts to subsequent evasive behavior like service termination or missing logs.","url":"https://attack.mitre.org/detectionstrategies/DET0595#AN1633","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"DefensiveProcessList","description":"List of defensive services/processes (e.g., AV, EDR) monitored in the environment."},{"field":"AllowedModulePaths","description":"Whitelisted DLL/module paths normally loaded by defensive tools."},{"field":"CrashThreshold","description":"Number of abnormal terminations of defensive processes tolerated before triggering an alert."}],"live":true,"detection_strategies":["DET0595"],"techniques":["T1211"]},{"id":"AN1634","stix_id":"x-mitre-analytic--ecf26d05-48ef-43b2-bfc3-4ea331be735b","name":"Analytic 1634","description":"Detects kernel- or user-space exploitation attempts targeting auditd, AV daemons, or security monitoring agents. Defender observation includes unexpected segfaults, privilege escalation attempts from low-privileged processes, or modifications to security binaries. Correlates exploitation attempts with subsequent gaps in logging or terminated processes.","url":"https://attack.mitre.org/detectionstrategies/DET0595#AN1634","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of suspicious exploit binaries targeting security daemons","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Segfaults, kernel oops, or crashes in security software processes","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"WatchedBinaries","description":"List of critical security daemons (e.g., auditd, falco, AV agents) to monitor for exploitation."},{"field":"CrashPatterns","description":"Regex or patterns for kernel/syslog errors correlated with exploitation attempts."}],"live":true,"detection_strategies":["DET0595"],"techniques":["T1211"]},{"id":"AN1635","stix_id":"x-mitre-analytic--88d9dbea-cc85-4c94-a368-e5c1a603854b","name":"Analytic 1635","description":"Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs.","url":"https://attack.mitre.org/detectionstrategies/DET0595#AN1635","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Abnormal terminations of com.apple.security.* or 3rd-party security daemons","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"execve: Unsigned or unnotarized processes launched with high privileges","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"SecurityDaemons","description":"Monitored Apple and third-party EDR/AV daemon names."},{"field":"UnsignedProcessThreshold","description":"Number of unsigned high-privilege executions before alerting."}],"live":true,"detection_strategies":["DET0595"],"techniques":["T1211"]},{"id":"AN1636","stix_id":"x-mitre-analytic--458038e6-60a2-47d2-bd55-675e77f0e279","name":"Analytic 1636","description":"Detects exploitation of IaaS cloud security boundaries to evade defense controls. Defender perspective includes anomalous API calls that bypass audit logging, disable monitoring, or manipulate guardrails (e.g., CloudTrail tampering). Correlation highlights when exploitation attempts precede sudden absence of expected telemetry.","url":"https://attack.mitre.org/detectionstrategies/DET0595#AN1636","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"StopLogging, DeleteTrail, UpdateTrail: API calls that disable or modify logging services","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"CriticalAPIs","description":"List of sensitive cloud API operations that should be rare and tightly monitored."},{"field":"TimeWindow","description":"Duration for correlation of API exploitation with sudden logging gaps."}],"live":true,"detection_strategies":["DET0595"],"techniques":["T1211"]},{"id":"AN1637","stix_id":"x-mitre-analytic--77c3b78a-fb34-4040-9dda-057e8eca3362","name":"Analytic 1637","description":"Detects adversary abuse of SaaS platform vulnerabilities to bypass logging, monitoring, or consent boundaries. Defender perspective focuses on abnormal application integration events, missing audit logs, or API calls from unauthorized service principals that align with exploitation attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0595#AN1637","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"ApplicationModified, ConsentGranted: Unexpected app consent or modification events linked to security evasion","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MonitoredApps","description":"Applications and integrations expected in the environment; deviations may be suspect."},{"field":"ConsentAnomalyThreshold","description":"Threshold for anomalous OAuth or app consent events before flagging exploitation."}],"live":true,"detection_strategies":["DET0595"],"techniques":["T1211"]}],"live":true,"version":"1.0","techniques":["T1211"]}],"sigma_rules":[{"id":"48d91a3a-2363-43ba-a456-ca71ac3da5c2","title":"Audit CVE Event","author":"Florian Roth (Nextron Systems), Zach Mathis","status":"test","level":"critical","date":"2020-01-15","modified":"2022-10-22","description":"Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.\nMS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.\nUnfortunately, that is about the only instance of CVEs being written to this log.\n","references":["https://twitter.com/VM_vivisector/status/1217190929330655232","https://twitter.com/DidierStevens/status/1217533958096924676","https://twitter.com/FlemmingRiis/status/1217147415482060800","https://www.youtube.com/watch?v=ebmW42YYveI","https://nullsec.us/windows-event-log-audit-cve/"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.stealth","attack.t1203","attack.privilege-escalation","attack.t1068","attack.t1211","attack.credential-access","attack.t1212","attack.lateral-movement","attack.t1210","attack.impact","attack.t1499.004"],"path":"rules/windows/builtin/application/microsoft-windows_audit_cve/win_audit_cve.yml","techniques":["T1203","T1068","T1211","T1212","T1210","T1499.004"],"cves":[]},{"id":"545a5da6-f103-4919-a519-e9aec1026ee4","title":"Microsoft Malware Protection Engine Crash","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-09","modified":"2023-04-14","description":"This rule detects a suspicious crash of the Microsoft Malware Protection Engine","references":["https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5","https://technet.microsoft.com/en-us/library/security/4022344"],"logsource":{"product":"windows","service":"application"},"tags":["attack.stealth","attack.defense-impairment","attack.t1211","attack.t1685"],"path":"rules/windows/builtin/application/application_error/win_application_error_msmpeng_crash.yml","techniques":["T1211","T1685"],"cves":[]},{"id":"6c82cf5c-090d-4d57-9188-533577631108","title":"Microsoft Malware Protection Engine Crash - WER","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-09","modified":"2023-04-14","description":"This rule detects a suspicious crash of the Microsoft Malware Protection Engine","references":["https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5","https://technet.microsoft.com/en-us/library/security/4022344"],"logsource":{"product":"windows","service":"application"},"tags":["attack.stealth","attack.defense-impairment","attack.t1211","attack.t1685"],"path":"rules/windows/builtin/application/windows_error_reporting/win_application_msmpeng_crash_wer.yml","techniques":["T1211","T1685"],"cves":[]},{"id":"ae9b0bd7-8888-4606-b444-0ed7410cb728","title":"Writing Of Malicious Files To The Fonts Folder","author":"Sreeman","status":"test","level":"medium","date":"2020-04-21","modified":"2022-03-08","description":"Monitors for the hiding possible malicious files in the C:\\Windows\\Fonts\\ location. This folder doesn't require admin privillege to be written and executed from.","references":["https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1211","attack.t1059","attack.persistence","attack.execution"],"path":"rules/windows/process_creation/proc_creation_win_susp_hiding_malware_in_fonts_folder.yml","techniques":["T1211","T1059"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2022-21999","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}