T1574.001 DLL
Sub-technique of T1574 Hijack Execution Flow
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.(Citation:…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Winnti Pipemon Characteristicscriticalstable · windows
- APT27 - Emissary Panda Activitycriticaltest · windows
- Winnti Malware HK University Campaigncriticaltest · windows
- Suspicious Unsigned Thor Scanner Executionhighstable · windows
- Aruba Network Service Potential DLL Sideloadinghightest · windows
- DHCP Callout DLL Installationhightest · windows
- DHCP Server Error Failed Loading the CallOut DLLhightest · windows
- DHCP Server Loaded the CallOut DLLhightest · windows
- DLL Search Order Hijackig Via Additional Space in Pathhightest · windows
- DLL Sideloading Of ShellChromeAPI.DLLhightest · windows
- DLL Sideloading by VMware Xfer Utilityhightest · windows
- DNS Server Error Failed Loading the ServerLevelPluginDLLhightest · windows
- Diamond Sleet APT DLL Sideloading Indicatorshightest · windows
- Fax Service DLL Search Order Hijackhightest · windows
- HackTool - Powerup Write Hijack DLLhightest · windows
- Lazarus APT DLL Sideloading Activityhightest · windows
- Malicious DLL File Dropped in the Teams or OneDrive Folderhightest · windows
- Microsoft Defender Blocked from Loading Unsigned DLLhightest · windows
- Microsoft Office DLL Sideloadhightest · windows
- New DNS ServerLevelPluginDll Installedhightest · windows
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXEhightest · windows
- Pingback Backdoor Activityhightest · windows
- Pingback Backdoor DLL Loading Activityhightest · windows
- Pingback Backdoor File Indicatorshightest · windows
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXEhightest · windows
Showing 25 of 40.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.