kevmap

TechniquesT1574 › AN0610

AN0610 Analytic 0610

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables.</p>
Detects
T1574 Hijack Execution Flow
Part of
DET0218 Detection Strategy for Hijack Execution Flow across OS platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLopen/write syscalls targeting /etc/ld.so.preload or binaries in /usr/binDC0061 File Modification
linux:syslogService restart with modified executable pathDC0041 Service Metadata
linux:osqueryProcess execution with LD_PRELOAD or modified library pathDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MonitoredDirectoriesDirectories where binary replacement should trigger alerts.
EnvVarMonitorsEnvironment variables like LD_PRELOAD or PATH to monitor.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2016-1010Adobe Flash Player and AIRMapped
CVE-2017-6742Cisco IOS and IOS XE SoftwareMapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR)Mapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-3038Google Chromium Network ServiceMapped
CVE-2022-41073Microsoft WindowsMapped
CVE-2022-41328Fortinet FortiOSMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNMapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-5217Google Chromium libvpxMapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-21762Fortinet FortiOSMapped
CVE-2025-27363FreeType FreeTypeMapped