{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","url":"https://attack.mitre.org/techniques/T1574/008","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0564","stix_id":"x-mitre-detection-strategy--9050bfb8-840d-4464-b4e8-7a0dbdece715","name":"Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking","url":"https://attack.mitre.org/detectionstrategies/DET0564","analytics":[{"id":"AN1560","stix_id":"x-mitre-analytic--578c821c-f8e3-45e7-a9b4-9aed6c84309a","name":"Analytic 1560","description":"Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0564#AN1560","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SuspiciousBinaryList","description":"Common system utilities often hijacked (e.g., net.exe, cmd.exe, powershell.exe, python.exe)."},{"field":"MonitoredDirectories","description":"Directories where executables should not normally be written (e.g., application folders, user profile subdirs)."},{"field":"TimeWindow","description":"Correlation window between file creation and subsequent process execution."},{"field":"ParentProcessBaseline","description":"Expected parent processes for critical system binaries, deviations may indicate hijacking."}],"live":true,"detection_strategies":["DET0564"],"techniques":["T1574.008"]}],"live":true,"version":"1.0","techniques":["T1574.008"]}],"sigma_rules":[{"id":"933f0bb5-0681-4fe7-8a17-4e6cccbaac44","title":"Potential Notepad++ CVE-2025-49144 Exploitation","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-26","modified":null,"description":"Detects potential exploitation of CVE-2025-49144, a local privilege escalation vulnerability in Notepad++ installers (v8.8.1 and prior) where the installer calls regsvr32.exe without specifying the full path.\nThis allows an attacker to execute arbitrary code with elevated privileges by placing a malicious regsvr32.exe alongside this Legitimate Notepad++ installer.\nThe vulnerability is triggered when the installer attempts to register the NppShell.dll file, which is a component of Notepad++.\n","references":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49144","https://x.com/NullSecurityX/status/1937444064867029179"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.008","cve.2025-49144","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-49144/proc_creation_win_exploit_cve_2025_49144.yml","techniques":["T1574.008"],"cves":["CVE-2025-49144"]},{"id":"b2ddd389-f676-4ac4-845a-e00781a48e5f","title":"Using SettingSyncHost.exe as LOLBin","author":"Anton Kutepov, oscd.community","status":"test","level":"high","date":"2020-02-05","modified":"2021-11-27","description":"Detects using SettingSyncHost.exe to run hijacked binary","references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.008"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml","techniques":["T1574.008"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}