Detecttechnique

D3-SCASystem Call Analysis

System Call Analysis

Definition

Analyzing system calls to determine whether a process is exhibiting unauthorized behavior.

Defends against40

TypeTargetConfidenceTier
TechniqueProcess Discoveryt1057100%live
SubTechniqueCMSTPt1218.003100%live
TechniqueRemote System Discoveryt1018100%live
TechniqueSystem Information Discoveryt1082100%live
SubTechniqueBypass User Account Controlt1548.002100%live
SubTechniqueMatch Legitimate Name or Locationt1036.005100%live
SubTechniqueParent PID Spoofingt1134.004100%live
SubTechniqueMavinjectt1218.013100%live
TechniqueNative APIt1106100%live
SubTechniqueSQL Stored Procedurest1505.001100%live
SubTechniqueAsynchronous Procedure Callt1055.004100%live
SubTechniqueTime Based Evasiont1497.003100%live
TechniqueScheduled Task/Jobt1053100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniqueCompiled HTML Filet1218.001100%live
TechniqueScreen Capturet1113100%live
SubTechniqueDynamic-link Library Injectiont1055.001100%live
TechniqueWindows Management Instrumentationt1047100%live
SubTechniqueElevated Execution with Promptt1548.004100%live
SubTechniqueAppCert DLLst1546.009100%live
SubTechniqueCredentials from Web Browserst1555.003100%live
SubTechniquePtrace System Callst1055.008100%live
SubTechniqueProcess Doppelgängingt1055.013100%live
TechniqueSystem Network Connections Discoveryt1049100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueLocal Data Stagingt1074.001100%live
SubTechniqueControl Panelt1218.002100%live
SubTechniqueMshtat1218.005100%live
TechniqueSystem Owner/User Discoveryt1033100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live

Showing top 30 of 40 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
System Call Filtering
Defence
Process Spawn Analysis
Defence
System Init Config Analysis
Defence
System File Analysis
Defence
Script Execution Analysis
Defence
Application Protocol Command Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.