{"id":"T1622","name":"Debugger Evasion","url":"https://attack.mitre.org/techniques/T1622","tactics":["stealth","discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0371","stix_id":"x-mitre-detection-strategy--22f3a380-389d-44f7-a846-c6223fc06ddd","name":"Detection Strategy for Debugger Evasion (T1622)","url":"https://attack.mitre.org/detectionstrategies/DET0371","analytics":[{"id":"AN1045","stix_id":"x-mitre-analytic--d5f0b652-3699-45af-97e6-81e7426558bd","name":"Analytic 1045","description":"Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0371#AN1045","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"NtQueryInformationProcess","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"}],"mutable_elements":[{"field":"ApiCallFrequencyThreshold","description":"Number of repeated debug-related API calls allowed before raising an alert"},{"field":"ProcessAllowList","description":"Legitimate debuggers or developer tools that may trigger similar behaviors"}],"live":true,"detection_strategies":["DET0371"],"techniques":["T1622"]},{"id":"AN1046","stix_id":"x-mitre-analytic--e4a9dd91-3354-40c8-a55c-941d53f2ddec","name":"Analytic 1046","description":"Monitor access to /proc/self/status where TracerPID field is queried, as this is a common technique for debugger detection. Detect processes that attempt to trigger exceptions intentionally and monitor whether exception handling indicates presence of a debugger.","url":"https://attack.mitre.org/detectionstrategies/DET0371#AN1046","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/read: Access to /proc/self/status with focus on TracerPID field","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"MonitoredPaths","description":"Set of /proc paths to monitor for suspicious access"},{"field":"SyscallThreshold","description":"Rate of syscalls (open/read) used to detect repeated probing for debug artifacts"}],"live":true,"detection_strategies":["DET0371"],"techniques":["T1622"]},{"id":"AN1047","stix_id":"x-mitre-analytic--c78d2e09-07d7-48ef-add1-bde622e502a2","name":"Analytic 1047","description":"Detect suspicious calls to sysctl or ptrace API used to determine if a process is being debugged. Monitor for processes that flood OutputDebugString equivalents or generate abnormal exceptions to evade analysis.","url":"https://attack.mitre.org/detectionstrategies/DET0371#AN1047","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"ptrace: Processes invoking ptrace with PTRACE_TRACEME flag","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PtraceInvocationThreshold","description":"Number of ptrace calls in a time window that should raise suspicion"},{"field":"DevToolExclusionList","description":"Exclude known developer tools and monitoring agents"}],"live":true,"detection_strategies":["DET0371"],"techniques":["T1622"]}],"live":true,"version":"1.0","techniques":["T1622"]}],"sigma_rules":[{"id":"811e0002-b13b-4a15-9d00-a613fce66e42","title":"PUA - Process Hacker Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-10-10","modified":"2024-11-23","description":"Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc).\nProcess Hacker is a tool to view and manipulate processes, kernel options and other low level options.\nThreat actors abused older vulnerable versions to manipulate system processes.\n","references":["https://processhacker.sourceforge.io/","https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1622","attack.t1564","attack.t1543"],"path":"rules/windows/process_creation/proc_creation_win_pua_process_hacker.yml","techniques":["T1622","T1564","T1543"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2022-42475","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2015-3113","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}