Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means. Windows processes often leverage these API functions to perform tasks that require reusable system resources. Windows API functions are typically stored in dynamic-link libraries (DLLs) as exported functions. (Citation: Enterprise ATT&CK) One type of hooking seen in ICS involves redirecting calls to these functions via import address table (IAT) hooking. IAT hooking uses modifications to a process IAT, where pointers to imported API functions are stored. (Citation: Nicolas Falliere, Liam O Murchu, Eric Chien February 2011)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Jump Host
is related to Programmable Logic Controller (PLC)
is related to Human-Machine Interface (HMI)
is related to Data Gateway
is related to Switch
is related to Control Server
is related to Data Historian
is related to Intelligent Electronic Device (IED)
is related to Workstation
is related to Safety Controller
is related to Application Server
is related to Remote Terminal Unit (RTU)
is related to Routers
is related to Distributed Control System (DCS) Controller
is related to Programmable Automation Controller (PAC)
is related to Virtual Private Network (VPN) Server
is related to Firewall
is part of Privilege Escalation
is blocked by Restrict Library Loading
is blocked by Audit
is blocked by Detection of Hooking
Impressum German English