T1055.001 Dynamic-link Library Injection
Sub-technique of T1055 Process Injection
Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges. DLL injection is a method of executing arbitrary code in the address space of a separate live process. DLL injection is commonly performed by writing the path to a DLL in the virtual address space of the target process before loading the DLL by…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- HackTool - Potential CobaltStrike Process Injectionhightest · windows
- ManageEngine Endpoint Central Dctask64.EXE Potential Abusehightest · windows
- Mavinject Inject DLL Into Running Processhightest · windows
- Renamed Mavinject.EXE Executionhightest · windows
- Renamed ZOHO Dctask64 Executionhightest · windows
- TAIDOOR RAT DLL Loadhightest · windows
- Potential DLL Injection Or Execution Using Tracker.exemediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.