AppCert DLLs

T1546.009

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes. Dynamic-link libraries (DLLs) that are specified in the AppCertDLLs Registry key under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\ are loaded into every process that calls the ubiquitously used application programming interface (API) functions CreateProcess, CreateProcessAsUser, CreateProcessWithLoginW, CreateProcessWithTokenW, or WinExec.

Similar to Process Injection, this value can be abused to obtain elevated privileges by causing a malicious DLL to be loaded and run in the context of separate processes on the computer. Malicious AppCert DLLs may also provide persistence by continuously being triggered by API activity.

Detection rules4

Rules on DetectionCode tagged with T1546.009.

Sigma2

RuleLevelLog source
New DLL Added to AppCertDlls Registry Keymediumwindows / registry_event
Session Manager Autorun Keys Modificationmediumwindows / registry_set

Splunk2

RuleTypeRiskData source
Windows AppCertDLL Modification Via Command LineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows AppCertDLL Modification Via RegistryAnomalyNULLSysmon EventID 13

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwarePUNCHBUGGY

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

References1

  1. Elastic Process Injection July 2017 Open source
    Hosseini, A. (2017, July 18). Ten Process Injection Techniques: A Technical Survey Of Common And Trending Process Injection Techniques. Retrieved December 7, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.