{"id":"T1546.012","name":"Image File Execution Options Injection","url":"https://attack.mitre.org/techniques/T1546/012","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0422","stix_id":"x-mitre-detection-strategy--d65ea5cc-52c6-4ec6-98a8-eef0be23ee72","name":"Detection Strategy for IFEO Injection on Windows","url":"https://attack.mitre.org/detectionstrategies/DET0422","analytics":[{"id":"AN1186","stix_id":"x-mitre-analytic--3e5b15b0-e6b2-402a-9c4f-e483c968a38e","name":"Analytic 1186","description":"Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens.","url":"https://attack.mitre.org/detectionstrategies/DET0422#AN1186","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time delta for correlating registry modification and debugger-triggered execution"},{"field":"TargetBinary","description":"Specific executables that trigger defenders’ alerts when IFEO values are set"},{"field":"ParentProcessAnomaly","description":"Tunable logic for detecting parent-child anomalies (e.g., non-standard parent processes)"},{"field":"TokenElevationContext","description":"May require tuning based on normal SYSTEM or admin process elevation patterns"}],"live":true,"detection_strategies":["DET0422"],"techniques":["T1546.012"]}],"live":true,"version":"1.0","techniques":["T1546.012"]}],"sigma_rules":[{"id":"36803969-5421-41ec-b92f-8500f79c23b0","title":"Potential Persistence Via GlobalFlags","author":"Karneades, Jonhnathan Ribeiro, Florian Roth","status":"test","level":"high","date":"2018-04-11","modified":"2023-06-05","description":"Detects registry persistence technique using the GlobalFlags and SilentProcessExit keys","references":["https://oddvar.moe/2018/04/10/persistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe/","https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.012","car.2013-01-002"],"path":"rules/windows/registry/registry_set/registry_set_persistence_globalflags.yml","techniques":["T1546.012"],"cves":[]},{"id":"707e097c-e20f-4f67-8807-1f72ff4500d6","title":"Potential Persistence Via App Paths Default Property","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-10","modified":"2023-08-17","description":"Detects changes to the \"Default\" property for keys located in the \\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\ registry. Which might be used as a method of persistence\nThe entries found under App Paths are used primarily for the following purposes.\nFirst, to map an application's executable file name to that file's fully qualified path.\nSecond, to prepend information to the PATH environment variable on a per-application, per-process basis.\n","references":["https://www.hexacorn.com/blog/2013/01/19/beyond-good-ol-run-key-part-3/","https://learn.microsoft.com/en-us/windows/win32/shell/app-registration"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.012"],"path":"rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml","techniques":["T1546.012"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}