threatengine.sh
· ··:··
Sign in
free plan Dashboard Stack Monitoring Notifications Watchlist Account & tokens API docs Pricing Sign out
Home/ CVE-2026-54104/ Attack path

Attack path: Credential API Hooking

Kill-chain expansion via actor co-occurrence analysis  ·  16 techniques  ·  15 detectable  ·  1 detection gap
Entry point: CVE-2026-54104 T1056.004
Initial Access
T1189
Drive-by Compromise
✓ sigma
2.1x lift
Persistence
T1547.004
Winlogon Helper DLL
✓ sigma
19.8x lift
Credential Access
T1557
Adversary-in-the-Middle
✓ sigma
3.8x lift
T1539
Steal Web Session Cookie
✓ sigma
3.3x lift
T1555.003
Credentials from Web Browsers
✓ sigma
1.7x lift
Collection
T1056.004
Credential API Hooking
× no rule
entry point
T1056.002
GUI Input Capture
✓ sigma
8.3x lift
T1185
Browser Session Hijacking
✓ sigma
7.6x lift
T1115
Clipboard Data
✓ sigma
1.8x lift
T1113
Screen Capture
✓ sigma
1.8x lift
T1114.001
Local Email Collection
✓ sigma
C2
T1090.001
Internal Proxy
✓ sigma
1.5x lift
T1102
Web Service
✓ sigma
Impact
T1565.002
Transmitted Data Manipulation
✓ sigma
8.8x lift
T1565.001
Stored Data Manipulation
✓ sigma
5.5x lift
T1565
Data Manipulation
✓ sigma
4.2x lift
Entry point (from CVE) Detection rule available Detection gap - potential blind spot Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.
Sigma rules Full technique
SOC and Response
CVE triage
Stack monitoring
Am I affected
IOC triage
KEV catalog
Recently exploited
Daily brief
Change tracking
Detection Engineering
Detection coverage workspace
Saved stacks
SIEM query builder
Detection rules
D3FEND
Threat Hunting
Threat actors
ATT&CK techniques
Attack paths
Indicators
Ransomware groups
Atomic tests
Red Team and Pentest
Exploitability triage
Recon pack
Attack paths
CAPEC patterns
Adversary emulation
Compliance and GRC
Framework mapping
Control assessment
Audit view
Atlas Search Threat actors Techniques Detection coverage Tools & malware CWE CAPEC KEV catalog Package vulns
About All capabilities Pricing API docs Privacy policy Terms of service
threatengine.sh
Are you sure?
We use one first-party cookie to remember how you found us, only if you allow it. Everything the site needs to work uses essential cookies. See our privacy policy.