Compliance Node Overview
MITRE ATT&CK T1574 covers adversary hijacking of legitimate program execution flow to load malicious code. Sub-techniques include DLL Side-Loading (T1574.002), DLL Search Order Hijacking (T1574.001), DYLIB Hijacking (T1574.004), Executable Path Hijacking (T1574.007), Path Interception (T1574.008/009), COR_PROFILER (T1574.012). APT groups (APT41, Lazarus, ToddyCat) and commercial spyware (Pegasus) routinely use DLL side-loading. Compliance: NIST 800-53 SI-7, CM-7, ISO 27001 A.8.7, A.8.32, A.8.19, PCI DSS Req 6.4.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1574/
SHA-256 integrity: 45da48f11c6f1b93533e7782e13ff12d930d1f8b8f93dac0842ce56ce2187510
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574: Hijack Execution Flow (https://attack.mitre.org/techniques/T1574/) with 12 sub-techniques
- NIST SP 800-53 Rev 5: SI-7, CM-7
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access