{"id":"T1574.005","name":"Executable Installer File Permissions Weakness","url":"https://attack.mitre.org/techniques/T1574/005","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0038","stix_id":"x-mitre-detection-strategy--07b1eb42-4f7b-4420-972e-2f28f17c0fa0","name":"Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness","url":"https://attack.mitre.org/detectionstrategies/DET0038","analytics":[{"id":"AN0108","stix_id":"x-mitre-analytic--4f132f21-1287-4fc2-a13e-d7770d856610","name":"Analytic 0108","description":"Executables written or modified in installer directories (e.g., %TEMP% subdirectories or Program Files installer paths) followed by execution under elevated context. Defender observes abnormal file replacement activity, process creation by installer processes pointing to attacker-supplied binaries, and unexpected module loads in elevated processes.","url":"https://attack.mitre.org/detectionstrategies/DET0038#AN0108","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredDirectories","description":"Specific writable directories to monitor (e.g., %TEMP%, C:\\ProgramData, installer unpack paths)."},{"field":"HashBaseline","description":"Known good hashes of installer binaries to detect replacement."},{"field":"TimeWindow","description":"Correlation interval between file overwrite and execution event."},{"field":"UserContext","description":"Differentiate expected admin-installer execution vs. anomalous user writes."}],"live":true,"detection_strategies":["DET0038"],"techniques":["T1574.005"]}],"live":true,"version":"1.0","techniques":["T1574.005"]}],"sigma_rules":[{"id":"99c8be4f-3087-4f9f-9c24-8c7e257b442e","title":"Setup16.EXE Execution With Custom .Lst File","author":"frack113","status":"test","level":"medium","date":"2024-12-01","modified":null,"description":"Detects the execution of \"Setup16.EXE\" and old installation utility with a custom \".lst\" file.\nThese \".lst\" file can contain references to external program that \"Setup16.EXE\" will execute.\nAttackers and adversaries might leverage this as a living of the land utility.\n","references":["https://www.hexacorn.com/blog/2024/10/12/the-sweet16-the-oldbin-lolbin-called-setup16-exe/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.005"],"path":"rules/windows/process_creation/proc_creation_win_setup16_custom_lst_execution.yml","techniques":["T1574.005"],"cves":[]},{"id":"c484e533-ee16-4a93-b6ac-f0ea4868b2f1","title":"HackTool - SharpUp PrivEsc Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2022-08-20","modified":"2023-02-13","description":"Detects the use of SharpUp, a tool for local privilege escalation","references":["https://github.com/GhostPack/SharpUp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.discovery","attack.execution","attack.stealth","attack.t1615","attack.t1569.002","attack.t1574.005"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sharpup.yml","techniques":["T1615","T1569.002","T1574.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}