Log source category
image_load log source Sigma rules
125 Sigma detection rules in the library use the image_load log source, mostly on windows. The image_load category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Products
FoggyWeb Backdoor DLL Loading
criticalDetects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
windows
Malicious DLL Load By Compromised 3CXDesktopApp
criticalDetects DLL load activity of known compromised DLLs used in by the compromised 3CXDesktopApp
windows
Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
windows
Abusable DLL Potential Sideloading From Suspicious Location
highDetects potential DLL sideloading of DLLs that are known to be abused from suspicious locations
windows
APT PRIVATELOG Image Load Pattern
highDetects an image load pattern as seen when a tool named PRIVATELOG is used and rarely observed under legitimate circumstances
windows
Aruba Network Service Potential DLL Sideloading
highDetects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access "arubanetsvc.exe" process using DLL Search Order Hijacking
windows
BaaUpdate.exe Suspicious DLL Load
highDetects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking. This technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94) which can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.
windows
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
highDetects both of CVE-2022-30190 (Follina) and DogWalk vulnerabilities exploiting msdt.exe binary to load the "sdiageng.dll" library
windows
Diamond Sleet APT DLL Sideloading Indicators
highDetects DLL sideloading activity seen used by Diamond Sleet APT
windows
DLL Loaded From Suspicious Location Via Cmspt.EXE
highDetects cmstp loading "dll" or "ocx" files from suspicious locations
windows
DLL Sideloading Of ShellChromeAPI.DLL
highDetects processes loading the non-existent DLL "ShellChromeAPI". One known example is the "DeviceEnroller" binary in combination with the "PhoneDeepLink" flag tries to load this DLL. Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
windows
DotNet CLR DLL Loaded By Scripting Applications
highDetects .NET CLR DLLs being loaded by scripting applications such as wscript or cscript. This could be an indication of potential suspicious execution.
windows
Fax Service DLL Search Order Hijack
highThe Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.
windows
GAC DLL Loaded Via Office Applications
highDetects any GAC DLL being loaded by an Office Product
windows
HackTool - SharpEvtMute DLL Load
highDetects the load of EvtMuteHook.dll, a key component of SharpEvtHook, a tool that tampers with the Windows event logs
windows
HackTool - SILENTTRINITY Stager DLL Load
highDetects SILENTTRINITY stager dll loading activity
windows
Kapeka Backdoor Loaded Via Rundll32.EXE
highDetects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.
windows
Katz Stealer DLL Loaded
highDetects loading of DLLs associated with Katz Stealer malware 2025 variants. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. The process that loads these DLLs are very likely to be malicious.
windows
Lazarus APT DLL Sideloading Activity
highDetects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company
windows
Load Of RstrtMgr.DLL By A Suspicious Process
highDetects the load of RstrtMgr DLL (Restart Manager) by a suspicious process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.
windows
Microsoft Office DLL Sideload
highDetects DLL sideloading of DLLs that are part of Microsoft Office from non standard location
windows
PCRE.NET Package Image Load
highDetects processes loading modules related to PCRE.NET package
windows
Pingback Backdoor DLL Loading Activity
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows
Potential appverifUI.DLL Sideloading
highDetects potential DLL sideloading of "appverifUI.dll"
windows
Potential COLDSTEEL Persistence Service DLL Load
highDetects a suspicious DLL load by an "svchost" process based on location and name that might be related to ColdSteel RAT. This DLL location and name has been seen used by ColdSteel as the service DLL for its persistence mechanism
windows
Potential CSharp Streamer RAT Loading .NET Executable Image
highDetects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.
windows
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
highDetects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe". Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".
windows
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
highDetects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.
windows
Potential DLL Sideloading Via comctl32.dll
highDetects potential DLL sideloading using comctl32.dll to obtain system privileges
windows
Potential DLL Sideloading Via VMware Xfer
highDetects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL
windows
Potential EACore.DLL Sideloading
highDetects potential DLL sideloading of "EACore.dll"
windows
Potential Edputil.DLL Sideloading
highDetects potential DLL sideloading of "edputil.dll"
windows
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.
windows
Potential Iviewers.DLL Sideloading
highDetects potential DLL sideloading of "iviewers.dll" (OLE/COM Object Interface Viewer)
windows
Potential JLI.dll Side-Loading
highDetects potential DLL side-loading of jli.dll. JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm, and others in order to load malicious payloads in context of legitimate Java processes.
windows
Potential Mpclient.DLL Sideloading
highDetects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.
windows
Potential Raspberry Robin Aclui Dll SideLoading
highDetects potential sideloading of malicious "aclui.dll" by OleView.This behavior was observed in Raspberry-Robin variants reported by chekpoint research on Feburary 2024.
windows
Potential Rcdll.DLL Sideloading
highDetects potential DLL sideloading of rcdll.dll
windows
Potential RjvPlatform.DLL Sideloading From Non-Default Location
highDetects potential DLL sideloading of "RjvPlatform.dll" by "SystemResetPlatform.exe" located in a non-default location.
windows
Potential SmadHook.DLL Sideloading
highDetects potential DLL sideloading of "SmadHook.dll", a DLL used by SmadAV antivirus
windows
Potential System DLL Sideloading From Non System Locations
highDetects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.).
windows
Potential Vcruntime140 DLL Sideloading
highDetects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library. Threat actors have been observed using DLL sideloading techniques to load malicious payloads under the guise of legitimate applications such as SqlWriter, SqlDumper etc. Notably, APT29 has been documented leveraging WinELOADER to sideload vcruntime140.dll for executing malicious code.
windows
Potential Waveedit.DLL Sideloading
highDetects potential DLL sideloading of "waveedit.dll", which is part of the Nero WaveEditor audio editing software.
windows
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
highDetects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories. These DLLs contain the MiniDumpWriteDump function, which can be abused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.
windows
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
highDetects rundll32 loading a renamed comsvcs.dll to dump process memory
windows
Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
highDetects the load of dbghelp/dbgcore DLL (used to make memory dumps) by suspicious processes. Tools like ProcessHacker and some attacker tradecract use MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.
windows
Suspicious Unsigned Thor Scanner Execution
highDetects loading and execution of an unsigned thor scanner binary.
windows
Suspicious Volume Shadow Copy VSS_PS.dll Load
highDetects the image load of vss_ps.dll by uncommon executables. This DLL is used by the Volume Shadow Copy Service (VSS) to manage shadow copies of files and volumes. It is often abused by attackers to delete or manipulate shadow copies, which can hinder forensic investigations and data recovery efforts. The fact that it is loaded by processes that are not typically associated with VSS operations can indicate suspicious activity.
windows
Suspicious Volume Shadow Copy Vssapi.dll Load
highDetects the image load of VSS DLL by uncommon executables
windows
System Control Panel Item Loaded From Uncommon Location
highDetects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.
windows
Time Travel Debugging Utility Usage - Image
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows
Trusted Path Bypass via Windows Directory Spoofing
highDetects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification. This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.
windows
UAC Bypass Using Iscsicpl - ImageLoad
highDetects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
windows
UAC Bypass With Fake DLL
highAttempts to load dismcore.dll after dropping it
windows
Unsigned Mfdetours.DLL Sideloading
highDetects DLL sideloading of unsigned "mfdetours.dll". Executing "mftrace.exe" can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.
windows
VBA DLL Loaded Via Office Application
highDetects VB DLL's loaded by an office application. Which could indicate the presence of VBA Macros.
windows
VMMap Unsigned Dbghelp.DLL Potential Sideloading
highDetects potential DLL sideloading of an unsigned dbghelp.dll by the Sysinternals VMMap.
windows
WMI Persistence - Command Line Event Consumer
highDetects WMI command line event consumers
windows
Wmiprvse Wbemcomn DLL Hijack
highDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
windows
Amsi.DLL Loaded Via LOLBIN Process
mediumDetects loading of "Amsi.dll" by a living of the land process. This could be an indication of a "PowerShell without PowerShell" attack
windows
Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
mediumDetects Clfs.sys being loaded by a process running from a potentially suspicious location. Clfs.sys is loaded as part of many CVEs exploits that targets Common Log File.
windows
CLR DLL Loaded Via Office Applications
mediumDetects CLR DLL being loaded by an Office Product
windows
CredUI.DLL Loaded By Uncommon Process
mediumDetects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".
windows
Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
mediumDetects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process. The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine. Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.
windows
DLL Load By System Process From Suspicious Locations
mediumDetects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
windows
DLL Names Used By SVR For GraphicalProton Backdoor
mediumHunts known SVR-specific DLL names.
windows
DotNET Assembly DLL Loaded Via Office Application
mediumDetects any assembly DLL being loaded by an Office Product
windows
Microsoft Excel Add-In Loaded From Uncommon Location
mediumDetects Microsoft Excel loading an Add-In (.xll) file from an uncommon location
windows
Microsoft VBA For Outlook Addin Loaded Via Outlook
mediumDetects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process
windows
MMC Loading Script Engines DLLs
mediumDetects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt to execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.
windows
Potential Antivirus Software DLL Sideloading
mediumDetects potential DLL sideloading of DLLs that are part of antivirus software suchas McAfee, Symantec...etc
windows
Potential AVKkid.DLL Sideloading
mediumDetects potential DLL sideloading of "AVKkid.dll"
windows
Potential CCleanerDU.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerDU.dll"
windows
Potential CCleanerReactivator.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerReactivator.dll"
windows
Potential Chrome Frame Helper DLL Sideloading
mediumDetects potential DLL sideloading of "chrome_frame_helper.dll"
windows
Potential CVE-2024-35250 Exploitation Activity
mediumDetects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
windows
Potential DLL Sideloading Of DBGCORE.DLL
mediumDetects DLL sideloading of "dbgcore.dll"
windows
Potential DLL Sideloading Of DBGHELP.DLL
mediumDetects potential DLL sideloading of "dbghelp.dll"
windows
Potential DLL Sideloading Of DbgModel.DLL
mediumDetects potential DLL sideloading of "DbgModel.dll"
windows
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
mediumDetects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location
windows
Potential DLL Sideloading Of MpSvc.DLL
mediumDetects potential DLL sideloading of "MpSvc.dll".
windows
Potential DLL Sideloading Of MsCorSvc.DLL
mediumDetects potential DLL sideloading of "mscorsvc.dll".
windows
Potential DLL Sideloading Using Coregen.exe
mediumDetect usage of the "coregen.exe" (Microsoft CoreCLR Native Image Generator) binary to sideload arbitrary DLLs.
windows
Potential DLL Sideloading Via ClassicExplorer32.dll
mediumDetects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software
windows
Potential DLL Sideloading Via JsSchHlp
mediumDetects potential DLL sideloading using JUSTSYSTEMS Japanese word processor
windows
Potential Goopdate.DLL Sideloading
mediumDetects potential DLL sideloading of "goopdate.dll", a DLL used by googleupdate.exe
windows
Potential Libvlc.DLL Sideloading
mediumDetects potential DLL sideloading of "libvlc.dll", a DLL that is legitimately used by "VLC.exe"
windows
Potential Mfdetours.DLL Sideloading
mediumDetects potential DLL sideloading of "mfdetours.dll". While using "mftrace.exe" it can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.
windows
Potential Python DLL SideLoading
mediumDetects potential DLL sideloading of Python DLL files.
windows
Potential RjvPlatform.DLL Sideloading From Default Location
mediumDetects loading of "RjvPlatform.dll" by the "SystemResetPlatform.exe" binary which can be abused as a method of DLL side loading since the "$SysReset" directory isn't created by default.
windows
Potential RoboForm.DLL Sideloading
mediumDetects potential DLL sideloading of "roboform.dll", a DLL used by RoboForm Password Manager
windows
Potential ShellDispatch.DLL Sideloading
mediumDetects potential DLL sideloading of "ShellDispatch.dll"
windows
Potential SolidPDFCreator.DLL Sideloading
mediumDetects potential DLL sideloading of "SolidPDFCreator.dll"
windows
Potential Vivaldi_elf.DLL Sideloading
mediumDetects potential DLL sideloading of "vivaldi_elf.dll"
windows
Potential Wazuh Security Platform DLL Sideloading
mediumDetects potential DLL side loading of DLLs that are part of the Wazuh security platform
windows
Potential WWlib.DLL Sideloading
mediumDetects potential DLL sideloading of "wwlib.dll"
windows
Potentially Suspicious Image Load of Offreg.dll
mediumDetects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
windows
Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
mediumDetects the image load of VSS DLL by uncommon executables
windows
PowerShell Core DLL Loaded By Non PowerShell Process
mediumDetects loading of essential DLLs used by PowerShell by non-PowerShell process. Detects behavior similar to meterpreter's "load powershell" extension.
windows
PowerShell Core DLL Loaded Via Office Application
mediumDetects PowerShell core DLL being loaded by an Office Product
windows
Remote DLL Load Via Rundll32.EXE
mediumDetects a remote DLL load event via "rundll32.exe".
windows
Suspicious WSMAN Provider Image Loads
mediumDetects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution.
windows
Third Party Software DLL Sideloading
mediumDetects DLL sideloading of DLLs that are part of third party software (zoom, discord....etc)
windows
Unsigned .node File Loaded
mediumDetects the loading of unsigned .node files. Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack. .node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code. This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
windows
Unsigned DLL Loaded by Windows Utility
mediumDetects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
windows
Unsigned Image Loaded Into LSASS Process
mediumLoading unsigned image (DLL, EXE) into LSASS process
windows
Unsigned Module Loaded by ClickOnce Application
mediumDetects unsigned module load by ClickOnce application.
windows
VMGuestLib DLL Sideload
mediumDetects DLL sideloading of VMGuestLib.dll by the WmiApSrv service.
windows
VMMap Signed Dbghelp.DLL Potential Sideloading
mediumDetects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.
windows
WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
mediumDetects the loading of dbgcore.dll or dbghelp.dll by WerFaultSecure.exe, which has been observed in EDR-Freeze attacks to suspend processes and evade detection. However, this behavior has also been observed during normal software installations, so further investigation is required to confirm malicious activity. When threat hunting, look for this activity in conjunction with other suspicious processes starting, network connections, or file modifications that occur shortly after the DLL load. Pay special attention to timing - if other malicious activities occur during or immediately after this library loading, it may indicate EDR evasion attempts. Also correlate with any EDR/AV process suspension events or gaps in security monitoring during the timeframe.
windows
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
mediumDetects signs of the WMI script host process "scrcons.exe" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.
windows
WMIC Loading Scripting Libraries
mediumDetects threat actors proxy executing code and bypassing application controls by leveraging wmic and the `/FORMAT` argument switch to download and execute an XSL file (i.e js, vbs, etc). It could be an indicator of SquiblyTwo technique, which uses Windows Management Instrumentation (WMI) to execute malicious code.
windows
Amsi.DLL Load By Uncommon Process
lowDetects loading of Amsi.dll by uncommon processes
windows
BITS Client BitsProxy DLL Loaded By Uncommon Process
lowDetects an uncommon process loading the "BitsProxy.dll". This DLL is used when the BITS COM instance or API is used. This detection can be used to hunt for uncommon processes loading this DLL in your environment. Which may indicate potential suspicious activity occurring.
windows
Load Of RstrtMgr.DLL By An Uncommon Process
lowDetects the load of RstrtMgr DLL (Restart Manager) by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.
windows
Microsoft Excel Add-In Loaded
lowDetects Microsoft Excel loading an Add-In (.xll) file
windows
Microsoft Word Add-In Loaded
lowDetects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.
windows
Potential 7za.DLL Sideloading
lowDetects potential DLL sideloading of "7za.dll"
windows
Potential Azure Browser SSO Abuse
lowDetects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user.
windows
Python Image Load By Non-Python Process
lowDetects the image load of "Python Core" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code. Various tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables. Threat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.
windows
Signed DLL Loaded With Missing PE Version Metadata
lowDetects the loading of a digitally signed DLL whose PE version-info resource is entirely missing. Legitimate signed DLLs from reputable vendors often carry populated metadata fields (Description, Company, Product, OriginalFileName, FileVersion). An attacker who signs a purpose-built or hollowed DLL with a stolen, mis-issued, or cheaply purchased code-signing certificate will often omit these fields, producing a valid signature with no accompanying version info. This pattern is observed in DLL side-loading, search-order hijacking, and certificate-abuse campaigns where signing is used purely to satisfy security-product trust checks. Hunting Hypothesis: - Investigate the signing certificate (issuer, subject, validity window, thumbprint) for disposable or recently issued CAs and cross-reference against known threat-actor certificates. - Examine the DLL's on-disk path relative to the loading process — paths outside standard system directories or inside application folders susceptible to search-order hijacking are high-priority leads. - Correlate with the parent process context; DLLs loaded into high-value targets such as lsass.exe, svchost.exe, or browser processes warrant immediate escalation. Note: The "selection_metadata_null" selection matches fields with a null value. Some backends may interpret null field conditions as "field does not exist" rather than "field has a null value", which would change the detection semantics. If your backend does not support or support null-value matching in different ways than expected, you may need to adjust the rule logic accordingly or remove the "selection_metadata_null" condition.
windows
System Drawing DLL Load
lowDetects processes loading "System.Drawing.ni.dll". This could be an indicator of potential Screen Capture.
windows
Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location
lowDetects the loading of the "taskschd.dll" module from a process that located in a potentially suspicious or uncommon directory. The loading of this DLL might indicate that the application have the capability to create a scheduled task via the "Schedule.Service" COM object. Investigation of the loading application and its behavior is required to determining if its malicious.
windows
WMI Module Loaded By Uncommon Process
lowDetects WMI modules being loaded by an uncommon process
windows
Windows Spooler Service Suspicious Binary Load
informationalDetect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
windows