Compliance Node Overview
MITRE ATT&CK T1574.013 (KernelCallbackTable) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own payloads. The KernelCallbackTable can be found in the Process Environment Block (PEB) and is initialized to an array of graphic functions available to a GUI process once user32.dll is loaded. An adversary may hijack the execution flow of a process using the KernelCallbackTable by replacing an original callback function with a malicious payload. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1574/013/
SHA-256 integrity: a4fc713df501a9800ea12ef8147e7c4837b075264c1472e52d02c6a40aa62183
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574.013: KernelCallbackTable (https://attack.mitre.org/techniques/T1574/013/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.