Native API
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations...
BY SOURCE
PROCEDURES (20)
Auto-extracted: 4 detections for process creation monitoring
Auto-extracted: 2 detections for lsass
Auto-extracted: 2 detections for lateral
Auto-extracted: 2 detections for script block
Auto-extracted: 2 detections for general monitoring
Auto-extracted: 1 detections for lsass
Auto-extracted: 1 detections for process access monitoring
Auto-extracted: 1 detections for process access
Auto-extracted: 1 detections for api
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for inject
Auto-extracted: 1 detections for token
Auto-extracted: 1 detections for lateral
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for process access
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for inject
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for network connection monitoring
Auto-extracted: 1 detections for api