{"id":"T1056.004","name":"Credential API Hooking","url":"https://attack.mitre.org/techniques/T1056/004","tactics":["collection","credential-access"],"platforms":["Windows","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0139","stix_id":"x-mitre-detection-strategy--d918611a-9d07-4f8b-b70e-2fe1c2f75faf","name":"Detection of Credential Harvesting via API Hooking","url":"https://attack.mitre.org/detectionstrategies/DET0139","analytics":[{"id":"AN0389","stix_id":"x-mitre-analytic--89e3c3a3-249e-4af3-8885-92c228d88b02","name":"Analytic 0389","description":"Detects credential harvesting via userland API hooking (e.g., SetWindowsHookEx, IAT, or inline patching) by correlating memory modifications with hook installation functions and suspicious module loads in credential-sensitive processes like lsass.exe, explorer.exe, or winlogon.exe.","url":"https://attack.mitre.org/detectionstrategies/DET0139#AN0389","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetProcess","description":"Credential-sensitive targets (e.g., explorer.exe, winlogon.exe) may vary by environment"},{"field":"AccessMask","description":"Tuning for access rights like 0x1FFFFF for full access vs. thread injection"},{"field":"TimeWindow","description":"Correlate memory access and hook setup in short windows (5–10 seconds)"}],"live":true,"detection_strategies":["DET0139"],"techniques":["T1056.004"]},{"id":"AN0390","stix_id":"x-mitre-analytic--c031c27b-4d05-406a-8538-04ce1df41d35","name":"Analytic 0390","description":"Detects credential interception via malicious LD_PRELOAD-based shared libraries loaded into ssh, sudo, or scp processes. Correlates environment variable injection, unexpected library loads, and memory patching behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0139#AN0390","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"LD_PRELOAD Logging","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"InjectedLibraryName","description":"Watch for user-defined suspicious .so files (e.g., libhook.so, libshadow.so)"},{"field":"TargetProcessName","description":"Hooked binaries vary by use case (e.g., ssh, login, gdm)"}],"live":true,"detection_strategies":["DET0139"],"techniques":["T1056.004"]},{"id":"AN0391","stix_id":"x-mitre-analytic--b8141218-1f71-4b65-a611-7c9c55038c4c","name":"Analytic 0391","description":"Detects DYLD_INSERT_LIBRARIES abuse to hook credential-sensitive applications by correlating process spawns with unauthorized library injection and monitoring changes to the __TEXT segment (code) of credential handling binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0139#AN0391","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"DYLD event subsystem","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"File Access Monitor","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"Memory Mappings","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"DYLDInjectedPath","description":"Tunable based on naming patterns or location of malicious dylibs"},{"field":"ParentProcessName","description":"Hooking attempts may stem from terminal.app, bash, or AppleScript-based launchers"}],"live":true,"detection_strategies":["DET0139"],"techniques":["T1056.004"]}],"live":true,"version":"1.0","techniques":["T1056.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}