Path Interception by Search Order Hijacking

T1574.008

Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org

About this technique

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program.

Search order hijacking occurs when an adversary abuses the order in which Windows searches for programs that are not given a path. Unlike DLL search order hijacking, the search order differs depending on the method that is used to execute the program. However, it is common for Windows to search in the directory of the initiating program before searching through the Windows system directory. An adversary who finds a program vulnerable to search order hijacking (i.e., a program that does not specify the path to an executable) may take advantage of this vulnerability by creating a program named after the improperly specified program and placing it within the initiating program's directory.

For example, "example.exe" runs "cmd.exe" with the command-line argument net user. An adversary may place a program called "net.exe" within the same directory as example.exe, "net.exe" will be run instead of the Windows system utility net. In addition, if an adversary places a program called "net.com" in the same directory as "net.exe", then cmd.exe /C net user will execute "net.com" instead of "net.exe" due to the order of executable extensions defined under PATHEXT.

Search order hijacking is also a common practice for hijacking DLL loads and is covered in DLL.

Detection rules2

Rules on DetectionCode tagged with T1574.008.

Sigma1

RuleLevelLog source
Using SettingSyncHost.exe as LOLBinhighwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows Get-Variable.EXE Execution from WindowsApps FolderAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
ToolEmpire

Empire contains modules that can discover and exploit search order hijacking vulnerabilities.

ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities.

References4

  1. Microsoft CreateProcess Open source
    Microsoft. (n.d.). CreateProcess function. Retrieved September 12, 2024.
  2. Microsoft Environment Property Open source
    Microsoft. (2011, October 24). Environment Property. Retrieved July 27, 2016.
  3. Microsoft WinExec Open source
    Microsoft. (n.d.). WinExec function. Retrieved September 12, 2024.
  4. Windows NT Command Shell Open source
    Tim Hill. (2014, February 2). The Windows NT Command Shell. Retrieved December 5, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.