Cross-source coverage

T1546.012 / ATT&CK

Event Triggered Execution: Image File Execution Options Injection

10 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application’s IFEO will be prepended to the application’s name, effectively launching the new process under the debugger (e.g., C:\dbg\ntsd.exe -g notepad.exe).

IFEOs can be set directly via the Registry or in Global Flags via the GFlags tool. IFEOs are represented as Debugger values in the Registry under HKLM\SOFTWARE{\Wow6432Node}\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ where <executable> is the binary on which the debugger is attached.

IFEOs can also enable an arbitrary monitor program to be launched when a specified program silently exits (i.e. is prematurely terminated by itself or a second, non kernel-mode process). Similar to debuggers, silent exit monitoring can be enabled through GFlags and/or by directly modifying IFEO and silent process exit Registry values in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\.

Similar to Accessibility Features, on Windows Vista and later as well as Windows Server 2008 and later, a Registry key may be modified that configures "cmd.exe," or another program that provides backdoor access, as a "debugger" for an accessibility program (ex: utilman.exe). After the Registry is modified, pressing the appropriate key combination at the login screen while at the keyboard or when connected with Remote Desktop Protocol will cause the "debugger" program to be executed with SYSTEM privileges.

Similar to Process Injection, these values may also be abused to obtain privilege escalation by causing a malicious executable to be loaded and run in the context of separate processes on the computer. Installing IFEO mechanisms may also provide Persistence via continuous triggered invocation.

Malware may also use IFEO to impair defenses by registering invalid debuggers that redirect and effectively disable various system and security applications.

Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0422

Detection Strategy for IFEO Injection on Windows

Windows Analytic 1186

Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens.

  • WinEventLog:Security EventCode=4657
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Sysmon EventCode=12

elastic/detection-rules

4 rules
Detection Severity Format
Image File Execution Options Injection Medium Elastic TOML
Suspicious WerFault Child Process Medium Elastic TOML
Uncommon Registry Persistence Change Medium Elastic TOML
Werfault ReflectDebugger Persistence Low Elastic TOML

SigmaHQ/sigma

2 rules
Detection Severity Format
Potential Persistence Via App Paths Default Property High Sigma
Potential Persistence Via GlobalFlags High Sigma

elastic/protections-artifacts

2 rules
Detection Severity Format
Potential Evasion via Stack Rumbling Undefined Elastic TOML
Suspicious Image File Execution Options Modification Undefined Elastic TOML

splunk/security_content

2 rules
Detection Severity Format
Registry Keys Used For Privilege Escalation Undefined SPL
Windows Event Triggered Image File Execution Options Injection Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.