Suspicious Image File Execution Options Debugger Hijack

PremiumReviewedSigma · Medium · v1
Category
registry_set
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the creation of a Debugger value under an Image File Execution Options subkey, which causes an attacker-chosen program to launch whenever the named executable runs. This technique enables both persistence and injection into a targeted process as described in the process injection survey.

Related detections9 linkedT1055 — drag to rearrange
Suspicious DllHost Spawned By MMC Without Arguments via PASTALOADER
Suspicious vbc.exe Spawned by Installer Process
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious Image File Execution Options Debugger Hijack (via registry_set)
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
Suspicious Image File Execution Options Debugger Hijack
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.