System Call Analysis
Description
Analyzing system calls to determine whether a process is exhibiting unauthorized behavior.
Mapped SPARTA techniques
1 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Analysis counters T1106 Native API; SafeMode's curated mapping records EX-0010 as addressing that same adversary behaviour in the space domain. System-call analysis applies wherever the flight executive mediates task requests for hardware and memory. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 40 in MITRE ATT&CK Enterprise
- T1007System Service Discovery
- T1010Application Window Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1036.005Match Legitimate Resource Name or Location
- T1047Windows Management Instrumentation
- T1049System Network Connections Discovery
- T1053Scheduled Task/Job
- T1055.001Dynamic-link Library Injection
- T1055.003Thread Execution Hijacking
- T1055.004Asynchronous Procedure Call
- T1055.005Thread Local Storage
- T1055.008Ptrace System Calls
- T1055.013Process Doppelgänging
- T1055.014VDSO Hijacking
- T1057Process Discovery
- T1074.001Local Data Staging
- T1082System Information Discovery
- T1106Native API
- T1113Screen Capture
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1140Deobfuscate/Decode Files or Information
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1218.013Mavinject
- T1220XSL Script Processing
- T1497.003Time Based Checks
- T1505.001SQL Stored Procedures
- T1518.001Security Software Discovery
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1548.002Bypass User Account Control
- T1548.004Elevated Execution with Prompt
- T1555.003Credentials from Web Browsers
Cite as SafeMode Space, d3fend D3-SCA.