{"id":"T1574.001","name":"DLL","url":"https://attack.mitre.org/techniques/T1574/001","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0201","stix_id":"x-mitre-detection-strategy--bd33de0c-1ed7-42ea-b77d-1fd5d33acd3b","name":"Detection Strategy for Hijack Execution Flow for DLLs","url":"https://attack.mitre.org/detectionstrategies/DET0201","analytics":[{"id":"AN0577","stix_id":"x-mitre-analytic--448ecbfb-2b38-4ecc-9c63-f7dd87339271","name":"Analytic 0577","description":"DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.","url":"https://attack.mitre.org/detectionstrategies/DET0201#AN0577","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedDllPaths","description":"Known safe DLL directories to suppress false positives (e.g., C:\\Windows\\System32)."},{"field":"ProcessAllowList","description":"Applications expected to load DLLs from non-standard locations (e.g., development tools)."},{"field":"TimeWindow","description":"Correlation interval between DLL file creation, registry changes, and module load."},{"field":"HashBaseline","description":"Baseline hashes for legitimate DLLs used to detect substitution."}],"live":true,"detection_strategies":["DET0201"],"techniques":["T1574.001"]}],"live":true,"version":"1.0","techniques":["T1574.001"]}],"sigma_rules":[{"id":"060d5ad4-3153-47bb-8382-43e5e29eda92","title":"Unsigned Module Loaded by ClickOnce Application","author":"@SerkinValery","status":"test","level":"medium","date":"2023-06-08","modified":null,"description":"Detects unsigned module load by ClickOnce application.","references":["https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_susp_clickonce_unsigned_module_loaded.yml","techniques":["T1574.001"],"cves":[]},{"id":"0a4f6091-223b-41f6-8743-f322ec84930b","title":"Suspicious GUP Usage","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-02-06","modified":"2022-08-13","description":"Detects execution of the Notepad++ updater in a suspicious directory, which is often used in DLL side-loading attacks","references":["https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_gup_suspicious_execution.yml","techniques":["T1574.001"],"cves":[]},{"id":"0b0ea3cc-99c8-4730-9c53-45deee2a4c86","title":"Microsoft Defender Blocked from Loading Unsigned DLL","author":"Bhabesh Raj","status":"test","level":"high","date":"2022-08-02","modified":"2022-09-28","description":"Detects Code Integrity (CI) engine blocking Microsoft Defender's processes (MpCmdRun and NisSrv) from loading unsigned DLLs which may be an attempt to sideload arbitrary DLL","references":["https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool"],"logsource":{"product":"windows","service":"security-mitigations"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/builtin/security_mitigations/win_security_mitigations_defender_load_unsigned_dll.yml","techniques":["T1574.001"],"cves":[]},{"id":"0e0bc253-07ed-43f1-816d-e1b220fe8971","title":"Potential RjvPlatform.DLL Sideloading From Non-Default Location","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-06-09","modified":null,"description":"Detects potential DLL sideloading of \"RjvPlatform.dll\" by \"SystemResetPlatform.exe\" located in a non-default location.","references":["https://twitter.com/0gtweet/status/1666716511988330499"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_rjvplatform_non_default_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"0f3a9db2-c17a-480e-a723-d1f1c547ab6a","title":"Potential Raspberry Robin Aclui Dll SideLoading","author":"Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2024-07-31","modified":null,"description":"Detects potential sideloading of malicious \"aclui.dll\" by OleView.This behavior was observed in Raspberry-Robin variants reported by chekpoint research on Feburary 2024.\n","references":["https://research.checkpoint.com/2024/raspberry-robin-keeps-riding-the-wave-of-endless-1-days/","https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/","https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/","https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/","https://strontic.github.io/xcyclopedia/library/aclui.dll-F883E9CA757B622B032FDCA5BF33D0DF.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2024/Malware/Raspberry-Robin/image_load_malware_raspberry_robin_side_load_aclui_oleview.yml","techniques":["T1574.001"],"cves":[]},{"id":"13fc89a9-971e-4ca6-b9dc-aa53a445bf40","title":"DHCP Server Loaded the CallOut DLL","author":"Dimitrios Slamaris","status":"test","level":"high","date":"2017-05-15","modified":"2022-12-25","description":"This rule detects a DHCP server in which a specified Callout DLL (in registry) was loaded","references":["https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html","https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx","https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/builtin/system/microsoft_windows_dhcp_server/win_system_susp_dhcp_config.yml","techniques":["T1574.001"],"cves":[]},{"id":"1908fcc1-1b92-4272-8214-0fbaf2fa5163","title":"Malicious DLL File Dropped in the Teams or OneDrive Folder","author":"frack113","status":"test","level":"high","date":"2022-08-12","modified":null,"description":"Detects creation of a malicious DLL file in the location where the OneDrive or Team applications\nUpon execution of the Teams or OneDrive application, the dropped malicious DLL file (\"iphlpapi.dll\") is sideloaded\n","references":["https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_iphlpapi_dll_sideloading.yml","techniques":["T1574.001"],"cves":[]},{"id":"193d5ccd-6f59-40c6-b5b0-8e32d5ddd3d1","title":"Xwizard.EXE Execution From Non-Default Location","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-09-20","modified":"2024-08-15","description":"Detects the execution of Xwizard tool from a non-default directory.\nWhen executed from a non-default directory, this utility can be abused in order to side load a custom version of \"xwizards.dll\".\n","references":["https://lolbas-project.github.io/lolbas/Binaries/Xwizard/","http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_xwizard_execution_non_default_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"1fbc0671-5596-4e17-8682-f020a0b995dc","title":"Potential CCleanerDU.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-07-13","modified":null,"description":"Detects potential DLL sideloading of \"CCleanerDU.dll\"","references":["https://lab52.io/blog/2344-2/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_ccleaner_du.yml","techniques":["T1574.001"],"cves":[]},{"id":"2092cacb-d77b-4f98-ab0d-32b32f99a054","title":"Potential Vivaldi_elf.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-08-03","modified":null,"description":"Detects potential DLL sideloading of \"vivaldi_elf.dll\"","references":["https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vivaldi_elf.yml","techniques":["T1574.001"],"cves":[]},{"id":"21117127-21c8-437a-ae03-4b51e5a8a088","title":"Small Sieve Malware CommandLine Indicator","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-19","modified":null,"description":"Detects specific command line argument being passed to a binary as seen being used by the malware Small Sieve.","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/small-sieve/NCSC-MAR-Small-Sieve.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Small-Sieve/proc_creation_win_malware_small_sieve_cli_arg.yml","techniques":["T1574.001"],"cves":[]},{"id":"24007168-a26b-4049-90d0-ce138e13a5cf","title":"Lazarus APT DLL Sideloading Activity","author":"Thurein Oo, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-10-18","modified":null,"description":"Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company","references":["https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/","https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","attack.g0032","detection.emerging-threats"],"path":"rules-emerging-threats/2023/TA/Lazarus/image_load_apt_lazarus_side_load_activity.yml","techniques":["T1574.001"],"cves":[]},{"id":"24b6cf51-6122-469e-861a-22974e9c1e5b","title":"Potential SmadHook.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-06-01","modified":null,"description":"Detects potential DLL sideloading of \"SmadHook.dll\", a DLL used by SmadAV antivirus","references":["https://research.checkpoint.com/2023/malware-spotlight-camaro-dragons-tinynote-backdoor/","https://www.qurium.org/alerts/targeted-malware-against-crph/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_smadhook.yml","techniques":["T1574.001"],"cves":[]},{"id":"259dda31-b7a3-444f-b7d8-17f96e8a7d0d","title":"Potential RjvPlatform.DLL Sideloading From Default Location","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-06-09","modified":null,"description":"Detects loading of \"RjvPlatform.dll\" by the \"SystemResetPlatform.exe\" binary which can be abused as a method of DLL side loading since the \"$SysReset\" directory isn't created by default.","references":["https://twitter.com/0gtweet/status/1666716511988330499"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_rjvplatform_default_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"273a8dd8-3742-4302-bcc7-7df5a80fe425","title":"VMMap Unsigned Dbghelp.DLL Potential Sideloading","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-07-28","modified":"2023-09-05","description":"Detects potential DLL sideloading of an unsigned dbghelp.dll by the Sysinternals VMMap.","references":["https://techcommunity.microsoft.com/t5/sysinternals-blog/zoomit-v7-1-procdump-2-0-for-linux-process-explorer-v17-05/ba-p/3884766"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vmmap_dbghelp_unsigned.yml","techniques":["T1574.001"],"cves":[]},{"id":"28a452f3-786c-4fd8-b8f2-bddbe9d616d1","title":"Creation of WerFault.exe/Wer.dll in Unusual Folder","author":"frack113","status":"test","level":"medium","date":"2022-05-09","modified":"2026-05-18","description":"Detects the creation of a file named \"WerFault.exe\" or \"wer.dll\" in an uncommon folder, which could be a sign of WerFault DLL hijacking.","references":["https://www.bleepingcomputer.com/news/security/hackers-are-now-hiding-malware-in-windows-event-logs/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_werfault_dll_hijacking.yml","techniques":["T1574.001"],"cves":[]},{"id":"2a297820-04ce-41f2-b60d-5afe139aaab3","title":"Signed DLL Loaded With Missing PE Version Metadata","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2026-05-21","modified":null,"description":"Detects the loading of a digitally signed DLL whose PE version-info resource is entirely missing.\nLegitimate signed DLLs from reputable vendors often carry populated metadata fields (Description, Company, Product, OriginalFileName, FileVersion).\nAn attacker who signs a purpose-built or hollowed DLL with a stolen, mis-issued, or cheaply purchased code-signing certificate will often omit these fields, producing a valid signature with no accompanying version info.\nThis pattern is observed in DLL side-loading, search-order hijacking, and certificate-abuse campaigns where signing is used purely to satisfy security-product trust checks.\n\nHunting Hypothesis:\n    - Investigate the signing certificate (issuer, subject, validity window, thumbprint) for disposable or recently issued CAs and cross-reference against known threat-actor certificates.\n    - Examine the DLL's on-disk path relative to the loading process — paths outside standard system directories or inside application folders susceptible to search-order hijacking are high-priority leads.\n    - Correlate with the parent process context; DLLs loaded into high-value targets such as lsass.exe, svchost.exe, or browser processes warrant immediate escalation.\n\nNote:\n    The \"selection_metadata_null\" selection matches fields with a null value.\n    Some backends may interpret null field conditions as \"field does not exist\" rather than \"field has a null value\", which would change the detection semantics.\n    If your backend does not support or support null-value matching in different ways than expected, you may need to adjust the rule logic accordingly or remove the \"selection_metadata_null\" condition.\n","references":["Internal Research"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.stealth","attack.execution","attack.t1574.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_win_signed_dll_no_metadata.yml","techniques":["T1574.001"],"cves":[]},{"id":"2b140a5c-dc02-4bb8-b6b1-8bdb45714cde","title":"System Control Panel Item Loaded From Uncommon Location","author":"Anish Bogati","status":"test","level":"high","date":"2024-01-09","modified":"2026-02-17","description":"Detects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.\n","references":["https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/","https://www.hexacorn.com/blog/2024/01/01/1-little-known-secret-of-hdwwiz-exe/","https://github.com/mhaskar/FsquirtCPLPoC","https://securelist.com/sidewinder-apt/114089/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_cpl_from_non_system_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"2bd63d53-84d4-4210-80ff-bf0658f1bf78","title":"Pingback Backdoor File Indicators","author":"Bhabesh Raj","status":"test","level":"high","date":"2021-05-05","modified":"2023-02-17","description":"Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel","https://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Pingback/file_event_win_malware_pingback_backdoor.yml","techniques":["T1574.001"],"cves":[]},{"id":"3121461b-5aa0-4a41-b910-66d25524edbb","title":"Winnti Malware HK University Campaign","author":"Florian Roth (Nextron Systems), Markus Neis","status":"test","level":"critical","date":"2020-02-01","modified":"2021-11-27","description":"Detects specific process characteristics of Winnti malware noticed in Dec/Jan 2020 in a campaign against Honk Kong universities","references":["https://www.welivesecurity.com/2020/01/31/winnti-group-targeting-universities-hong-kong/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","attack.g0044","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/Winnti/proc_creation_win_apt_winnti_mal_hk_jan20.yml","techniques":["T1574.001"],"cves":[]},{"id":"35a7dc42-bc6f-46e0-9f83-81f8e56c8d4b","title":"Pingback Backdoor DLL Loading Activity","author":"Bhabesh Raj","status":"test","level":"high","date":"2021-05-05","modified":"2023-02-17","description":"Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel","https://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Pingback/image_load_malware_pingback_backdoor.yml","techniques":["T1574.001"],"cves":[]},{"id":"3735d5ac-d770-4da0-99ff-156b180bc600","title":"Potential CCleanerReactivator.DLL Sideloading","author":"X__Junior","status":"test","level":"medium","date":"2023-07-13","modified":null,"description":"Detects potential DLL sideloading of \"CCleanerReactivator.dll\"","references":["https://lab52.io/blog/2344-2/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_ccleaner_reactivator.yml","techniques":["T1574.001"],"cves":[]},{"id":"418dc89a-9808-4b87-b1d7-e5ae0cb6effc","title":"Potential Mpclient.DLL Sideloading","author":"Bhabesh Raj","status":"test","level":"high","date":"2022-08-02","modified":"2023-08-04","description":"Detects potential sideloading of \"mpclient.dll\" by Windows Defender processes (\"MpCmdRun\" and \"NisSrv\") from their non-default directory.","references":["https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_windows_defender.yml","techniques":["T1574.001"],"cves":[]},{"id":"4c21b805-4dd7-469f-b47d-7383a8fcb437","title":"Potential Iviewers.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-03-21","modified":null,"description":"Detects potential DLL sideloading of \"iviewers.dll\" (OLE/COM Object Interface Viewer)","references":["https://www.secureworks.com/research/shadowpad-malware-analysis"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_iviewers.yml","techniques":["T1574.001"],"cves":[]},{"id":"4f6edb78-5c21-42ab-a558-fd2a6fc1fd57","title":"Potential 7za.DLL Sideloading","author":"X__Junior","status":"test","level":"low","date":"2023-06-09","modified":null,"description":"Detects potential DLL sideloading of \"7za.dll\"","references":["https://www.gov.pl/attachment/ee91f24d-3e67-436d-aa50-7fa56acf789d"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_7za.yml","techniques":["T1574.001"],"cves":[]},{"id":"4fc0deee-0057-4998-ab31-d24e46e0aba4","title":"Potential System DLL Sideloading From Non System Locations","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-14","modified":"2026-07-10","description":"Detects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.).","references":["https://hijacklibs.net/","https://blog.cyble.com/2022/07/21/qakbot-resurfaces-with-new-playbook/","https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading/","https://github.com/XForceIR/SideLoadHunter/blob/cc7ef2e5d8908279b0c4cee4e8b6f85f7b8eed52/SideLoads/README.md","https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/","https://www.sophos.com/en-us/blog/finding-minhook-in-a-sideloading-attack-and-sweden-too"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_from_non_system_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"50f852e6-af22-4c78-9ede-42ef36aa3453","title":"Potential Azure Browser SSO Abuse","author":"Den Iuzvyk","status":"test","level":"low","date":"2020-07-15","modified":"2023-04-18","description":"Detects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser.\nAn attacker can use this to authenticate to Azure AD in a browser as that user.\n","references":["https://posts.specterops.io/requesting-azure-ad-request-tokens-on-azure-ad-joined-machines-for-browser-sso-2b0409caad30"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_dll_azure_microsoft_account_token_provider_dll_load.yml","techniques":["T1574.001"],"cves":[]},{"id":"552b6b65-df37-4d3e-a258-f2fc4771ae54","title":"Potential Antivirus Software DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"medium","date":"2022-08-17","modified":"2025-10-07","description":"Detects potential DLL sideloading of DLLs that are part of antivirus software suchas McAfee, Symantec...etc","references":["https://hijacklibs.net/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_antivirus.yml","techniques":["T1574.001"],"cves":[]},{"id":"5ba243e5-8165-4cf7-8c69-e1d3669654c1","title":"Potential DLL Sideloading Of MpSvc.DLL","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema","status":"test","level":"medium","date":"2024-07-11","modified":null,"description":"Detects potential DLL sideloading of \"MpSvc.dll\".","references":["https://hijacklibs.net/entries/microsoft/built-in/mpsvc.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_mpsvc.yml","techniques":["T1574.001"],"cves":[]},{"id":"602a1f13-c640-4d73-b053-be9a2fa58b96","title":"HackTool - Powerup Write Hijack DLL","author":"Subhash Popuri (@pbssubhash)","status":"test","level":"high","date":"2021-08-21","modified":"2024-06-27","description":"Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation.\nIn it's default mode, it builds a self deleting .bat file which executes malicious command.\nThe detection rule relies on creation of the malicious bat file (debug.bat by default).\n","references":["https://powersploit.readthedocs.io/en/latest/Privesc/Write-HijackDll/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_hktl_powerup_dllhijacking.yml","techniques":["T1574.001"],"cves":[]},{"id":"6360757a-d460-456c-8b13-74cf0e60cceb","title":"Potential DLL Sideloading Via comctl32.dll","author":"Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash)","status":"test","level":"high","date":"2022-12-16","modified":"2022-12-19","description":"Detects potential DLL sideloading using comctl32.dll to obtain system privileges","references":["https://github.com/binderlabs/DirCreate2System","https://github.com/sailay1996/awesome_windows_logical_bugs/blob/60cbb23a801f4c3195deac1cc46df27c225c3d07/dir_create2system.txt"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_comctl32.yml","techniques":["T1574.001"],"cves":[]},{"id":"6414b5cd-b19d-447e-bb5e-9f03940b5784","title":"Potential DLL Sideloading Of DBGHELP.DLL","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"medium","date":"2022-10-25","modified":"2025-10-07","description":"Detects potential DLL sideloading of \"dbghelp.dll\"","references":["https://hijacklibs.net/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_dbghelp.yml","techniques":["T1574.001"],"cves":[]},{"id":"68654bf0-4412-43d5-bfe8-5eaa393cd939","title":"Potential DLL Sideloading Via JsSchHlp","author":"frack113","status":"test","level":"medium","date":"2022-12-14","modified":null,"description":"Detects potential DLL sideloading using JUSTSYSTEMS Japanese word processor","references":["https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/","http://www.windowexe.com/bbs/board.php?q=jsschhlp-exe-c-program-files-common-files-justsystem-jsschhlp-jsschhlp"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_jsschhlp.yml","techniques":["T1574.001"],"cves":[]},{"id":"6b98b92b-4f00-4f62-b4fe-4d1920215771","title":"Potential DLL Sideloading Of Non-Existent DLLs From System Folders","author":"Nasreddine Bencherchali (Nextron Systems), SBousseaden","status":"test","level":"high","date":"2022-12-09","modified":"2026-01-24","description":"Detects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts.\nPhantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.\n","references":["http://remoteawesomethoughts.blogspot.com/2019/05/windows-10-task-schedulerservice.html","https://clement.notin.org/blog/2020/09/12/CVE-2020-7315-McAfee-Agent-DLL-injection/","https://decoded.avast.io/martinchlumecky/png-steganography/","https://github.com/Wh04m1001/SysmonEoP","https://itm4n.github.io/cdpsvc-dll-hijacking/","https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992","https://securelist.com/passiveneuron-campaign-with-apt-implants-and-cobalt-strike/117745/","https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/","https://www.hexacorn.com/blog/2013/12/08/beyond-good-ol-run-key-part-5/","https://www.hexacorn.com/blog/2025/06/14/wermgr-exe-boot-offdmpsvc-dll-lolbin/","https://www.hexacorn.com/blog/2025/06/14/wpr-exe-boottrace-phantom-dll-axeonoffhelper-dll-lolbin/","https://x.com/0gtweet/status/1564131230941122561"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_non_existent_dlls.yml","techniques":["T1574.001"],"cves":[]},{"id":"6e78b74f-c762-4800-82ad-f66787f10c8a","title":"Potential Rcdll.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-03-13","modified":"2023-03-15","description":"Detects potential DLL sideloading of rcdll.dll","references":["https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_rcdll.yml","techniques":["T1574.001"],"cves":[]},{"id":"7002aa10-b8d4-47ae-b5ba-51ab07e228b9","title":"Potential Mpclient.DLL Sideloading Via Defender Binaries","author":"Bhabesh Raj","status":"test","level":"high","date":"2022-08-01","modified":"2023-08-04","description":"Detects potential sideloading of \"mpclient.dll\" by Windows Defender processes (\"MpCmdRun\" and \"NisSrv\") from their non-default directory.","references":["https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_mpcmdrun_dll_sideload_defender.yml","techniques":["T1574.001"],"cves":[]},{"id":"70e8e9b4-6a93-4cb7-8cde-da69502e7aff","title":"VMGuestLib DLL Sideload","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-12-01","modified":null,"description":"Detects DLL sideloading of VMGuestLib.dll by the WmiApSrv service.","references":["https://decoded.avast.io/martinchlumecky/png-steganography/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vmguestlib.yml","techniques":["T1574.001"],"cves":[]},{"id":"71b31e99-9ad0-47d4-aeb5-c0ca3928eeeb","title":"Potential Waveedit.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-06-14","modified":null,"description":"Detects potential DLL sideloading of \"waveedit.dll\", which is part of the Nero WaveEditor audio editing software.","references":["https://www.trendmicro.com/en_us/research/23/f/behind-the-scenes-unveiling-the-hidden-workings-of-earth-preta.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_waveedit.yml","techniques":["T1574.001"],"cves":[]},{"id":"72ca7c75-bf85-45cd-aca7-255d360e423c","title":"Potential Chrome Frame Helper DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"medium","date":"2022-08-17","modified":"2023-05-15","description":"Detects potential DLL sideloading of \"chrome_frame_helper.dll\"","references":["https://hijacklibs.net/entries/3rd_party/google/chrome_frame_helper.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_chrome_frame_helper.yml","techniques":["T1574.001"],"cves":[]},{"id":"73d70463-75c9-4258-92c6-17500fe972f2","title":"Winnti Pipemon Characteristics","author":"Florian Roth (Nextron Systems), oscd.community","status":"stable","level":"critical","date":"2020-07-30","modified":"2021-11-27","description":"Detects specific process characteristics of Winnti Pipemon malware reported by ESET","references":["https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","attack.g0044","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/Winnti/proc_creation_win_apt_winnti_pipemon.yml","techniques":["T1574.001"],"cves":[]},{"id":"75edd3fd-7146-48e5-9848-3013d7f0282c","title":"DHCP Server Error Failed Loading the CallOut DLL","author":"Dimitrios Slamaris, @atc_project (fix)","status":"test","level":"high","date":"2017-05-15","modified":"2022-12-25","description":"This rule detects a DHCP server error in which a specified Callout DLL (in registry) could not be loaded","references":["https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html","https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx","https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/builtin/system/microsoft_windows_dhcp_server/win_system_susp_dhcp_config_failed.yml","techniques":["T1574.001"],"cves":[]},{"id":"7a3b6d1f-4a2b-4f8c-9d7e-e9f8cbf21a35","title":"Potential JLI.dll Side-Loading","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-07-25","modified":"2025-10-06","description":"Detects potential DLL side-loading of jli.dll.\nJLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm,\nand others in order to load malicious payloads in context of legitimate Java processes.\n","references":["https://securelist.com/apt41-in-africa/116986/","https://lab52.io/blog/snake-keylogger-in-geopolitical-affairs-abuse-of-trusted-java-utilities-in-cybercrime-operations/","https://hijacklibs.net/entries/3rd_party/oracle/jli.html","https://www.proofpoint.com/us/blog/threat-insight/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_jli.yml","techniques":["T1574.001"],"cves":[]},{"id":"7b4f794b-590a-4ad4-ba18-7964a2832205","title":"Renamed Vmnat.exe Execution","author":"elhoim","status":"test","level":"high","date":"2022-09-09","modified":"2023-02-03","description":"Detects renamed vmnat.exe or portable version that can be used for DLL side-loading","references":["https://twitter.com/malmoeb/status/1525901219247845376"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_renamed_vmnat.yml","techniques":["T1574.001"],"cves":[]},{"id":"8289bf8c-4aca-4f5a-9db3-dc3d7afe5c10","title":"Unsigned Binary Loaded From Suspicious Location","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-03","modified":"2022-09-28","description":"Detects Code Integrity (CI) engine blocking processes from loading unsigned DLLs residing in suspicious locations","references":["https://github.com/nasbench/EVTX-ETW-Resources/blob/45fd5be71a51aa518b1b36d4e1f36af498084e27/ETWEventsList/CSV/Windows11/21H2/W11_21H2_Pro_20220719_22000.795/Providers/Microsoft-Windows-Security-Mitigations.csv"],"logsource":{"product":"windows","service":"security-mitigations"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/builtin/security_mitigations/win_security_mitigations_unsigned_dll_from_susp_location.yml","techniques":["T1574.001"],"cves":[]},{"id":"828af599-4c53-4ed2-ba4a-a9f835c434ea","title":"Fax Service DLL Search Order Hijack","author":"NVISO","status":"test","level":"high","date":"2020-05-04","modified":"2022-06-02","description":"The Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.","references":["https://windows-internals.com/faxing-your-way-to-system/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_ualapi.yml","techniques":["T1574.001"],"cves":[]},{"id":"829a3bdf-34da-4051-9cf4-8ed221a8ae4f","title":"Microsoft Office DLL Sideload","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"high","date":"2022-08-17","modified":"2023-03-15","description":"Detects DLL sideloading of DLLs that are part of Microsoft Office from non standard location","references":["https://hijacklibs.net/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_office_dlls.yml","techniques":["T1574.001"],"cves":[]},{"id":"844f8eb2-610b-42c8-89a4-47596e089663","title":"Potential ShellDispatch.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-06-20","modified":null,"description":"Detects potential DLL sideloading of \"ShellDispatch.dll\"","references":["https://www.hexacorn.com/blog/2023/06/07/this-lolbin-doesnt-exist/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_shelldispatch.yml","techniques":["T1574.001"],"cves":[]},{"id":"90ae0469-0cee-4509-b67f-e5efcef040f7","title":"Aruba Network Service Potential DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-22","modified":"2023-03-15","description":"Detects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access \"arubanetsvc.exe\" process using DLL Search Order Hijacking","references":["https://twitter.com/wdormann/status/1616581559892545537?t=XLCBO9BziGzD7Bmbt8oMEQ&s=09"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_aruba_networks_virtual_intranet_access.yml","techniques":["T1574.001"],"cves":[]},{"id":"9313dc13-d04c-46d8-af4a-a930cc55d93b","title":"Potential DLL Sideloading Via VMware Xfer","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-02","modified":"2023-02-17","description":"Detects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL","references":["https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vmware_xfer.yml","techniques":["T1574.001"],"cves":[]},{"id":"948a0953-f287-4806-bbcb-3b2e396df89f","title":"Unsigned Mfdetours.DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-08-11","modified":null,"description":"Detects DLL sideloading of unsigned \"mfdetours.dll\". Executing \"mftrace.exe\" can be abused to attach to an arbitrary process and force load any DLL named \"mfdetours.dll\" from the current directory of execution.","references":["Internal Research"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_mfdetours_unsigned.yml","techniques":["T1574.001"],"cves":[]},{"id":"952ed57c-8f99-453d-aee0-53a49c22f95d","title":"Potential AVKkid.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-08-03","modified":null,"description":"Detects potential DLL sideloading of \"AVKkid.dll\"","references":["https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_avkkid.yml","techniques":["T1574.001"],"cves":[]},{"id":"98ffaed4-aec2-4e04-9b07-31492fe68b3d","title":"VMMap Signed Dbghelp.DLL Potential Sideloading","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-09-05","modified":null,"description":"Detects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.","references":["https://techcommunity.microsoft.com/t5/sysinternals-blog/zoomit-v7-1-procdump-2-0-for-linux-process-explorer-v17-05/ba-p/3884766"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vmmap_dbghelp_signed.yml","techniques":["T1574.001"],"cves":[]},{"id":"9aa01d62-7667-4d3b-acb8-8cb5103e2014","title":"APT27 - Emissary Panda Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2018-09-03","modified":"2023-03-09","description":"Detects the execution of DLL side-loading malware used by threat group Emissary Panda aka APT27","references":["https://app.any.run/tasks/579e7587-f09d-4aae-8b07-472833262965","https://twitter.com/cyb3rops/status/1168863899531132929","https://research.nccgroup.com/2018/05/18/emissary-panda-a-potential-new-malicious-tool/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","attack.g0027","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/APT27/proc_creation_win_apt_apt27_emissary_panda.yml","techniques":["T1574.001"],"cves":[]},{"id":"9ca2bf31-0570-44d8-a543-534c47c33ed7","title":"Potential DLL Sideloading Of DBGCORE.DLL","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"medium","date":"2022-10-25","modified":"2025-10-06","description":"Detects DLL sideloading of \"dbgcore.dll\"","references":["https://hijacklibs.net/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_dbgcore.yml","techniques":["T1574.001"],"cves":[]},{"id":"9d3436ef-9476-4c43-acca-90ce06bdf33a","title":"DHCP Callout DLL Installation","author":"Dimitrios Slamaris","status":"test","level":"high","date":"2017-05-15","modified":"2023-08-17","description":"Detects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)","references":["https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html","https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx","https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.defense-impairment","attack.t1574.001","attack.t1112"],"path":"rules/windows/registry/registry_set/registry_set_dhcp_calloutdll.yml","techniques":["T1574.001","T1112"],"cves":[]},{"id":"9e1bef8d-0fff-46f6-8465-9aa54e128c1e","title":"Use Of Hidden Paths Or Files","author":"David Burkett, @signalblur","status":"test","level":"low","date":"2022-12-30","modified":null,"description":"Detects calls to hidden files or files located in hidden directories in NIX systems.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1564.001/T1564.001.md"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/linux/auditd/path/lnx_auditd_hidden_binary_execution.yml","techniques":["T1574.001"],"cves":[]},{"id":"a2edbce1-95c8-4291-8676-0d45146862b3","title":"Potential SolidPDFCreator.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-05-07","modified":null,"description":"Detects potential DLL sideloading of \"SolidPDFCreator.dll\"","references":["https://lab52.io/blog/new-mustang-pandas-campaing-against-australia/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_solidpdfcreator.yml","techniques":["T1574.001"],"cves":[]},{"id":"a5ea83a7-05a5-44c1-be2e-addccbbd8c03","title":"UAC Bypass With Fake DLL","author":"oscd.community, Dmitry Uchakin","status":"test","level":"high","date":"2020-10-06","modified":"2022-12-25","description":"Attempts to load dismcore.dll after dropping it","references":["https://steemit.com/utopian-io/@ah101/uac-bypassing-utility"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1548.002","attack.t1574.001"],"path":"rules/windows/image_load/image_load_uac_bypass_via_dism.yml","techniques":["T1548.002","T1574.001"],"cves":[]},{"id":"aeab5ec5-be14-471a-80e8-e344418305c2","title":"Potential PlugX Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-06-12","modified":"2023-02-03","description":"Detects the execution of an executable that is typically used by PlugX for DLL side loading starting from an uncommon location","references":["http://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/","https://countuponsecurity.com/2017/06/07/threat-hunting-in-the-enterprise-with-appcompatprocessor/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.s0013","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/PlugX/proc_creation_win_malware_plugx_susp_exe_locations.yml","techniques":["T1574.001"],"cves":[]},{"id":"b2400ffb-7680-47c0-b08a-098a7de7e7a9","title":"Pingback Backdoor Activity","author":"Bhabesh Raj","status":"test","level":"high","date":"2021-05-05","modified":"2023-02-17","description":"Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel","https://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Pingback/proc_creation_win_malware_pingback_backdoor.yml","techniques":["T1574.001"],"cves":[]},{"id":"b6188d2f-b3c4-4d2c-a17d-9706e0851af0","title":"Potential Goopdate.DLL Sideloading","author":"X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-15","modified":"2025-10-07","description":"Detects potential DLL sideloading of \"goopdate.dll\", a DLL used by googleupdate.exe","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_goopdate.yml","techniques":["T1574.001"],"cves":[]},{"id":"b6f91281-20aa-446a-b986-38a92813a18f","title":"DLL Search Order Hijackig Via Additional Space in Path","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-30","modified":null,"description":"Detects when an attacker create a similar folder structure to windows system folders such as (Windows, Program Files...)\nbut with a space in order to trick DLL load search order and perform a \"DLL Search Order Hijacking\" attack\n","references":["https://twitter.com/cyb3rops/status/1552932770464292864","https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_dll_sideloading_space_path.yml","techniques":["T1574.001"],"cves":[]},{"id":"bf9808c4-d24f-44a2-8398-b65227d406b6","title":"Potential Libvlc.DLL Sideloading","author":"X__Junior","status":"test","level":"medium","date":"2023-04-17","modified":null,"description":"Detects potential DLL sideloading of \"libvlc.dll\", a DLL that is legitimately used by \"VLC.exe\"","references":["https://www.trendmicro.com/en_us/research/23/c/earth-preta-updated-stealthy-strategies.html","https://hijacklibs.net/entries/3rd_party/vlc/libvlc.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_libvlc.yml","techniques":["T1574.001"],"cves":[]},{"id":"c0e0bdec-3e3d-47aa-9974-05539c999c89","title":"Registry Modification for OCI DLL Redirection","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-01-24","modified":null,"description":"Detects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings.\nThreat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.\n","references":["https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1112","attack.t1574.001"],"path":"rules/windows/registry/registry_set/registry_set_potential_oci_dll_redirection.yml","techniques":["T1112","T1574.001"],"cves":[]},{"id":"ca5583e9-8f80-46ac-ab91-7f314d13b984","title":"Potentially Suspicious Child Process of KeyScrambler.exe","author":"Swachchhanda Shrawan Poudel","status":"test","level":"medium","date":"2024-05-13","modified":null,"description":"Detects potentially suspicious child processes of KeyScrambler.exe","references":["https://twitter.com/DTCERT/status/1712785421845790799"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.stealth","attack.t1203","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_keyscrambler_susp_child_process.yml","techniques":["T1203","T1574.001"],"cves":[]},{"id":"caa02837-f659-466f-bca6-48bde2826ab4","title":"Potential DLL Sideloading Via ClassicExplorer32.dll","author":"frack113","status":"test","level":"medium","date":"2022-12-13","modified":null,"description":"Detects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software","references":["https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets","https://app.any.run/tasks/6d8cabb0-dcda-44b6-8050-28d6ce281687/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_classicexplorer32.yml","techniques":["T1574.001"],"cves":[]},{"id":"cbe51394-cd93-4473-b555-edf0144952d9","title":"DNS Server Error Failed Loading the ServerLevelPluginDLL","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-08","modified":"2023-02-05","description":"Detects a DNS server error in which a specified plugin DLL (in registry) could not be loaded","references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://technet.microsoft.com/en-us/library/cc735829(v=ws.10).aspx","https://twitter.com/gentilkiwi/status/861641945944391680"],"logsource":{"product":"windows","service":"dns-server"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/builtin/dns_server/win_dns_server_susp_server_level_plugin_dll.yml","techniques":["T1574.001"],"cves":[]},{"id":"cc4e02ba-9c06-48e2-b09e-2500cace9ae0","title":"Tasks Folder Evasion","author":"Sreeman","status":"test","level":"high","date":"2020-01-13","modified":"2022-12-25","description":"The Tasks folder in system32 and syswow64 are globally writable paths.\nAdversaries can take advantage of this and load or influence any script hosts or ANY .NET Application\nin Tasks to load and execute a custom assembly into cscript, wscript, regsvr32, mshta, eventvwr\n","references":["https://twitter.com/subTee/status/1216465628946563073","https://gist.github.com/am0nsec/8378da08f848424e4ab0cc5b317fdd26"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_task_folder_evasion.yml","techniques":["T1574.001"],"cves":[]},{"id":"cdb15e19-c2d0-432a-928e-e49c8c60dcf2","title":"Potential DLL Sideloading Of MsCorSvc.DLL","author":"Wietze Beukema","status":"test","level":"medium","date":"2024-07-11","modified":"2025-02-26","description":"Detects potential DLL sideloading of \"mscorsvc.dll\".","references":["https://hijacklibs.net/entries/microsoft/built-in/mscorsvc.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_mscorsvc.yml","techniques":["T1574.001"],"cves":[]},{"id":"d1b65d98-37d7-4ff6-b139-2d87c1af3042","title":"Diamond Sleet APT DLL Sideloading Indicators","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-10-24","modified":null,"description":"Detects DLL sideloading activity seen used by Diamond Sleet APT","references":["https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2023/TA/Diamond-Sleet/image_load_apt_diamond_sleet_side_load.yml","techniques":["T1574.001"],"cves":[]},{"id":"d2451be2-b582-4e15-8701-4196ac180260","title":"Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE","author":"Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2024-04-15","modified":null,"description":"Detects potential DLL side loading of \"KeyScramblerIE.dll\" by \"KeyScrambler.exe\".\nVarious threat actors and malware have been found side loading a masqueraded \"KeyScramblerIE.dll\" through \"KeyScrambler.exe\".\n","references":["https://thehackernews.com/2024/03/two-chinese-apt-groups-ramp-up-cyber.html","https://csirt-cti.net/2024/02/01/stately-taurus-continued-new-information-on-cyberespionage-attacks-against-myanmar-military-junta/","https://bazaar.abuse.ch/sample/5cb9876681f78d3ee8a01a5aaa5d38b05ec81edc48b09e3865b75c49a2187831/","https://twitter.com/Max_Mal_/status/1775222576639291859","https://twitter.com/DTCERT/status/1712785426895839339"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_keyscrambler.yml","techniques":["T1574.001"],"cves":[]},{"id":"d2605a99-2218-4894-8fd3-2afb7946514d","title":"Potential Mfdetours.DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-03","modified":null,"description":"Detects potential DLL sideloading of \"mfdetours.dll\". While using \"mftrace.exe\" it can be abused to attach to an arbitrary process and force load any DLL named \"mfdetours.dll\" from the current directory of execution.","references":["Internal Research"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_mfdetours.yml","techniques":["T1574.001"],"cves":[]},{"id":"d36f7c12-14a3-4d48-b6b8-774b9c66f44d","title":"Potential Python DLL SideLoading","author":"Swachchhanda Shrawan Poudel","status":"test","level":"medium","date":"2024-10-06","modified":"2025-08-18","description":"Detects potential DLL sideloading of Python DLL files.","references":["https://www.securonix.com/blog/seolurker-attack-campaign-uses-seo-poisoning-fake-google-ads-to-install-malware/","https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/","https://github.com/wietze/HijackLibs/tree/dc9c9f2f94e6872051dab58fbafb043fdd8b4176/yml/3rd_party/python"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_python.yml","techniques":["T1574.001"],"cves":[]},{"id":"d7a63acb-1284-49bc-bfea-7771146c8b1c","title":"Potential Vcruntime140 DLL Sideloading","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-01-12","modified":"2026-05-18","description":"Detects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library.\nThreat actors have been observed using DLL sideloading techniques to load malicious payloads under the guise of legitimate applications such as SqlWriter, SqlDumper etc.\nNotably, APT29 has been documented leveraging WinELOADER to sideload vcruntime140.dll for executing malicious code.\n","references":["https://www.mandiant.com/resources/blog/apt29-wineloader-german-political-parties","https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader","https://www.nextron-systems.com/2023/09/15/detecting-janelarat-with-yara-and-thor/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_vcruntime140.yml","techniques":["T1574.001"],"cves":[]},{"id":"db77ce78-7e28-4188-9337-cf30e2b3ba9f","title":"Potential Wazuh Security Platform DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-03-13","modified":"2023-05-12","description":"Detects potential DLL side loading of DLLs that are part of the Wazuh security platform","references":["https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_wazuh.yml","techniques":["T1574.001"],"cves":[]},{"id":"dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c","title":"Potential Initial Access via DLL Search Order Hijacking","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":null,"description":"Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d46dd4ac6866b4337ec126be8cee0e115467b3e8703794ba6f6df6432c806bc","https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1566","attack.t1566.001","attack.initial-access","attack.t1574","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_initial_access_dll_search_order_hijacking.yml","techniques":["T1566","T1566.001","T1574","T1574.001"],"cves":[]},{"id":"df6ecb8b-7822-4f4b-b412-08f524b4576c","title":"Creation Of Non-Existent System DLL","author":"Nasreddine Bencherchali (Nextron Systems), fornotes","status":"test","level":"medium","date":"2022-12-01","modified":"2026-01-24","description":"Detects creation of specific system DLL files that are  usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes.\nPhantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.\nThus, the creation of such DLLs may indicate preparation for phantom DLL hijacking attacks.\n","references":["http://remoteawesomethoughts.blogspot.com/2019/05/windows-10-task-schedulerservice.html","https://clement.notin.org/blog/2020/09/12/CVE-2020-7315-McAfee-Agent-DLL-injection/","https://decoded.avast.io/martinchlumecky/png-steganography/","https://github.com/blackarrowsec/redteam-research/tree/26e6fc0c0d30d364758fa11c2922064a9a7fd309/LPE%20via%20StorSvc","https://github.com/Wh04m1001/SysmonEoP","https://itm4n.github.io/cdpsvc-dll-hijacking/","https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992","https://securelist.com/passiveneuron-campaign-with-apt-implants-and-cobalt-strike/117745/","https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/","https://www.hexacorn.com/blog/2013/12/08/beyond-good-ol-run-key-part-5/","https://www.hexacorn.com/blog/2025/06/14/wermgr-exe-boot-offdmpsvc-dll-lolbin/","https://www.hexacorn.com/blog/2025/06/14/wpr-exe-boottrace-phantom-dll-axeonoffhelper-dll-lolbin/","https://x.com/0gtweet/status/1564131230941122561"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_create_non_existent_dlls.yml","techniques":["T1574.001"],"cves":[]},{"id":"e173ad47-4388-4012-ae62-bd13f71c18a8","title":"Potential DLL Sideloading Via DeviceEnroller.EXE","author":"@gott_cyber","status":"test","level":"medium","date":"2022-08-29","modified":"2023-02-04","description":"Detects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named \"ShellChromeAPI.dll\".\nAdversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter\n","references":["https://mobile.twitter.com/0gtweet/status/1564131230941122561","https://strontic.github.io/xcyclopedia/library/DeviceEnroller.exe-24BEF0D6B0ECED36BB41831759FDE18D.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_deviceenroller_dll_sideloading.yml","techniques":["T1574.001"],"cves":[]},{"id":"e2e01011-5910-4267-9c3b-4149ed5479cf","title":"Potential WWlib.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-05-18","modified":null,"description":"Detects potential DLL sideloading of \"wwlib.dll\"","references":["https://twitter.com/WhichbufferArda/status/1658829954182774784","https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/","https://securelist.com/apt-luminousmoth/103332/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_wwlib.yml","techniques":["T1574.001"],"cves":[]},{"id":"e4903324-1a10-4ed3-981b-f6fe3be3a2c2","title":"Potential Edputil.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-06-09","modified":null,"description":"Detects potential DLL sideloading of \"edputil.dll\"","references":["https://alternativeto.net/news/2023/5/cybercriminals-use-wordpad-vulnerability-to-spread-qbot-malware/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_edputil.yml","techniques":["T1574.001"],"cves":[]},{"id":"e49b5745-1064-4ac1-9a2e-f687bc2dd37e","title":"Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-05","modified":null,"description":"Detects potential DLL sideloading of \"libcurl.dll\" by the \"gup.exe\" process from an uncommon location","references":["https://labs.withsecure.com/publications/fin7-target-veeam-servers"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_gup_libcurl.yml","techniques":["T1574.001"],"cves":[]},{"id":"e5f5c693-52d7-4de5-88ae-afbfbce85595","title":"Unsigned .node File Loaded","author":"Jonathan Beierle (@hullabrian)","status":"experimental","level":"medium","date":"2025-11-22","modified":null,"description":"Detects the loading of unsigned .node files.\nAdversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack.\n.node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code.\nThis technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.\n","references":["https://www.coreycburton.com/blog/driploader-case-study","https://github.com/CoreyCBurton/DripLoaderNG","https://www.electronjs.org/docs/latest/tutorial/native-code-and-electron"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.privilege-escalation","attack.persistence","attack.stealth","attack.t1129","attack.t1574.001","attack.t1036.005"],"path":"rules/windows/image_load/image_load_dll_unsigned_node_load.yml","techniques":["T1129","T1574.001","T1036.005"],"cves":[]},{"id":"e61e8a88-59a9-451c-874e-70fcc9740d67","title":"New DNS ServerLevelPluginDll Installed","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-08","modified":"2023-08-17","description":"Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)","references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.defense-impairment","attack.t1574.001","attack.t1112"],"path":"rules/windows/registry/registry_set/registry_set_dns_server_level_plugin_dll.yml","techniques":["T1574.001","T1112"],"cves":[]},{"id":"e64c8ef3-9f98-40c8-b71e-96110991cb4c","title":"DLL Names Used By SVR For GraphicalProton Backdoor","author":"CISA","status":"test","level":"medium","date":"2023-12-18","modified":null,"description":"Hunts known SVR-specific DLL names.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001","detection.emerging-threats"],"path":"rules-emerging-threats/2023/TA/Cozy-Bear/image_load_apt_cozy_bear_graphical_proton_dlls.yml","techniques":["T1574.001"],"cves":[]},{"id":"ea5c131b-380d-49f9-aeb3-920694da4d4b","title":"Suspicious Unsigned Thor Scanner Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"stable","level":"high","date":"2023-10-29","modified":null,"description":"Detects loading and execution of an unsigned thor scanner binary.","references":["Internal Research"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_thor_unsigned_execution.yml","techniques":["T1574.001"],"cves":[]},{"id":"ebea773c-a8f1-42ad-a856-00cb221966e8","title":"DLL Sideloading by VMware Xfer Utility","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-02","modified":null,"description":"Detects execution of VMware Xfer utility (VMwareXferlogs.exe) from the non-default directory which may be an attempt to sideload arbitrary DLL","references":["https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_dll_sideload_vmware_xfer.yml","techniques":["T1574.001"],"cves":[]},{"id":"edd3ddc3-386f-4ba5-9ada-4376b2cfa7b5","title":"Potential EACore.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-08-03","modified":null,"description":"Detects potential DLL sideloading of \"EACore.dll\"","references":["https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_eacore.yml","techniques":["T1574.001"],"cves":[]},{"id":"ee4c5d06-3abc-48cc-8885-77f1c20f4451","title":"DLL Sideloading Of ShellChromeAPI.DLL","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-12-01","modified":null,"description":"Detects processes loading the non-existent DLL \"ShellChromeAPI\". One known example is the \"DeviceEnroller\" binary in combination with the \"PhoneDeepLink\" flag tries to load this DLL.\nAdversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter\n","references":["https://mobile.twitter.com/0gtweet/status/1564131230941122561","https://strontic.github.io/xcyclopedia/library/DeviceEnroller.exe-24BEF0D6B0ECED36BB41831759FDE18D.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_shell_chrome_api.yml","techniques":["T1574.001"],"cves":[]},{"id":"ee6cea48-c5b6-4304-a332-10fc6446f484","title":"Potential appverifUI.DLL Sideloading","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-06-20","modified":null,"description":"Detects potential DLL sideloading of \"appverifUI.dll\"","references":["https://web.archive.org/web/20220519091349/https://fatrodzianko.com/2020/02/15/dll-side-loading-appverif-exe/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_appverifui.yml","techniques":["T1574.001"],"cves":[]},{"id":"f63b56ee-3f79-4b8a-97fb-5c48007e8573","title":"New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-08","modified":"2023-02-05","description":"Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)","references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.defense-impairment","attack.t1574.001","attack.t1112"],"path":"rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml","techniques":["T1574.001","T1112"],"cves":[]},{"id":"f64c9b2d-b0ad-481d-9d03-7fc75020892a","title":"Potential RoboForm.DLL Sideloading","author":"X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-14","modified":null,"description":"Detects potential DLL sideloading of \"roboform.dll\", a DLL used by RoboForm Password Manager","references":["https://twitter.com/StopMalvertisin/status/1648604148848549888","https://twitter.com/t3ft3lb/status/1656194831830401024","https://www.roboform.com/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_robform.yml","techniques":["T1574.001"],"cves":[]},{"id":"f9df325d-d7bc-4a32-8a1a-2cc61dcefc63","title":"Third Party Software DLL Sideloading","author":"Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research)","status":"test","level":"medium","date":"2022-08-17","modified":null,"description":"Detects DLL sideloading of DLLs that are part of third party software (zoom, discord....etc)","references":["https://hijacklibs.net/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_third_party.yml","techniques":["T1574.001"],"cves":[]},{"id":"fef394cd-f44d-4040-9b18-95d92fe278c0","title":"Potential DLL Sideloading Of DbgModel.DLL","author":"Gary Lobermier","status":"test","level":"medium","date":"2024-07-11","modified":"2024-07-22","description":"Detects potential DLL sideloading of \"DbgModel.dll\"","references":["https://hijacklibs.net/entries/microsoft/built-in/dbgmodel.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"path":"rules/windows/image_load/image_load_side_load_dbgmodel.yml","techniques":["T1574.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}