Abnormal Security Association (SA) Pointer Retrieval

Detection of an out-of-bounds SA pointer retrieval in CryptoLib, indicating a potential exploit targeting the security association retrieval function, leading to system crashes.

STIX Pattern

[process:x_sa_pointer_retrieval != 'valid_range' AND process:image_ref.name = 'CryptoLib']

SPARTA TTPs

ID Name Description
EX-0009 Exploit Code Flaws Threats actors may identify and exploit flaws or weaknesses within the software running on-board the target SV. These attacks may be extremely targeted and tailored to specific coding errors introduced as a result of poor coding practices or they may target known issues in the commercial software components.
EX-0009.01 Flight Software Threat actors may abuse known or unknown flight software code flaws in order to further the attack campaign. In some cases, these code flaws can perpetuate throughout the victim SV, allowing access to otherwise segmented subsystems.