Cross-source coverage
T1218.013 / ATT&CK
System Binary Proxy Execution: Mavinject
3 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application Virtualization Injector, a Windows utility that can inject code into external processes as part of Microsoft Application Virtualization (App-V).
Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL). Since mavinject.exe may be digitally signed by Microsoft, proxying execution via this method may evade detection by security products because the execution is masked under a legitimate process.
In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:PowerShell
How MITRE says to detect it DET0433
Detecting Code Injection via mavinject.exe (App-V Injector)
Windows Analytic 1207
Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VM_WRITE/CREATE_THREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=10WinEventLog:SysmonEventCode=7WinEventLog:SysmonEventCode=11WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106WinEventLog:SysmonEventCode=3, 22
SigmaHQ/sigma
2 rules| Detection | Severity | Format |
|---|---|---|
| Mavinject Inject DLL Into Running Process | High | Sigma |
| Renamed Mavinject.EXE Execution | High | Sigma |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Windows Binary Proxy Execution Mavinject DLL Injection | Undefined | SPL |