• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Image File Execution Options (IFEO) Injection

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Rory Wagner@Sleuthifer
    •updated Jul 9, 2025•2•1•87

    Detects suspicious registry modifications for IFEO entries which can be used by attackers for persistence. This is based off of testing with Atomic Red Team tests - https://www.atomicredteam.io/atomic-red-team/atomics/T1546.012

    Microsoft Sentinel (KQL)

    Tags

    T1546.012 - Image File Execution Options InjectionTA0002 - ExecutionDS0007 - ImageT1622 - Debugger EvasionTA0003 - PersistenceTA0005 - Defense EvasionRegistry Key ModificationRegistry Value SetRegistry EventWindowsWindows Defender AtpAzure Sentinelkql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?