Image File Execution Options Injection (T1546.012)

View on ATT&CK

In Playbook

Associated Tactics

  • Privilege Escalation
  • Persistence

Privilege Escalation (TA0004)

The adversary is trying to gain higher-level permissions. Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include: * SYSTEM/root level * local administrator * user account with admin-like access * user accounts with access to specific system or perform specific function These techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.

View on ATT&CK

Procedure Examples

Description Source(s)
Shanbhag, M. (2010, March 24). Image File Execution Options (IFEO). Retrieved December 18, 2017. Microsoft Dev Blog IFEO Mar 2010
Microsoft. (2017, May 23). GFlags Overview. Retrieved December 18, 2017. Microsoft GFlags Mar 2017
Marshall, D. & Griffin, S. (2017, November 28). Monitoring Silent Process Exit. Retrieved June 27, 2018. Microsoft Silent Process Exit NOV 2017
Moe, O. (2018, April 10). Persistence using GlobalFlags in Image File Execution Options - Hidden from Autoruns.exe. Retrieved June 27, 2018. Oddvar Moe IFEO APR 2018
Tilbury, C. (2014, August 28). Registry Analysis with CrowdResponse. Retrieved November 12, 2014. Tilbury 2014
Hosseini, A. (2017, July 18). Ten Process Injection Techniques: A Technical Survey Of Common And Trending Process Injection Techniques. Retrieved December 7, 2017. Elastic Process Injection July 2017
FSecure. (n.d.). Backdoor - W32/Hupigon.EMV - Threat Description. Retrieved December 18, 2017. FSecure Hupigon
Symantec. (2008, June 28). Trojan.Ushedix. Retrieved December 18, 2017. Symantec Ushedix June 2008