Compliance Node Overview
MITRE ATT&CK T1574.008 (Path Interception by Search Order Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program. Search order hijacking occurs when an adversary abuses the order in which Windows searches for programs that are not given a path. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1022 Restrict File and Directory Permissions, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1574/008/
SHA-256 integrity: cd789e0e81b939f33f100994be8e130fe71f544ec371a68dc0feca1d4b07bd1b
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574.008: Path Interception by Search Order Hijacking (https://attack.mitre.org/techniques/T1574/008/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access