DetailedDraft
CAPEC-579Replace Winlogon Helper DLL
Abstraction
Detailed
Status
Draft
Description
Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key can be modified that causes Winlogon to load a DLL on startup. Adversaries may take advantage of this feature to load adversarial code at startup.
Metadata: detailed CAPEC pattern, status draft. Underlying weakness: CWE-15. Mapped ATT&CK technique: [object Object]. Related CAPEC pattern: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | External Control of System or Configuration Settingcwe-15 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Winlogon Helper DLLt1547.004 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.