From e6eb91da4249e5e1059c50b109d3b7301a5a54d4 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Tue, 22 Sep 2026 12:36:26 +0200 Subject: [PATCH 01/10] add missing local true from lookup calls --- .../azure_ad_privileged_role_assigned.yml | 6 +++--- ...eged_role_assigned_to_service_principal.yml | 6 +++--- .../cloud/circle_ci_disable_security_job.yml | 6 +++--- ...calls_from_previously_unseen_user_roles.yml | 6 +++--- ...tance_created_by_previously_unseen_user.yml | 6 +++--- ...nce_created_in_previously_unused_region.yml | 6 +++--- ...ce_created_with_previously_unseen_image.yml | 6 +++--- ...ed_with_previously_unseen_instance_type.yml | 6 +++--- ...ance_modified_by_previously_unseen_user.yml | 6 +++--- ...ng_activity_from_previously_unseen_city.yml | 6 +++--- ...activity_from_previously_unseen_country.yml | 6 +++--- ...ivity_from_previously_unseen_ip_address.yml | 6 +++--- ..._activity_from_previously_unseen_region.yml | 6 +++--- .../cloud/kubernetes_nginx_ingress_lfi.yml | 6 +++--- .../o365_bec_email_hiding_rule_created.yml | 6 +++--- .../cloud/o365_privileged_role_assigned.yml | 6 +++--- ...eged_role_assigned_to_service_principal.yml | 6 +++--- .../endpoint/attacker_tools_on_endpoint.yml | 6 +++--- ...allation_of_typosquatted_python_package.yml | 6 +++--- ..._outbound_connection_to_suspicious_port.yml | 6 +++--- ...etect_remote_access_software_usage_file.yml | 6 +++--- ...t_remote_access_software_usage_fileinfo.yml | 6 +++--- ...ct_remote_access_software_usage_process.yml | 6 +++--- ...t_remote_access_software_usage_registry.yml | 6 +++--- .../first_time_seen_child_process_of_zoom.yml | 6 +++--- .../potential_password_in_username.yml | 6 +++--- ...processes_run_from_unexpected_locations.yml | 6 +++--- .../windows_ad_adminsdholder_acl_modified.yml | 6 +++--- ...dows_ad_dangerous_deny_acl_modification.yml | 6 +++--- ...ows_ad_dangerous_group_acl_modification.yml | 6 +++--- ...dows_ad_dangerous_user_acl_modification.yml | 6 +++--- ...ows_ad_dcshadow_privileges_acl_addition.yml | 18 +++++++++--------- ...domain_controller_audit_policy_disabled.yml | 6 +++--- ...dows_ad_domain_replication_acl_addition.yml | 14 +++++++------- .../windows_ad_domain_root_acl_deletion.yml | 6 +++--- ...windows_ad_domain_root_acl_modification.yml | 6 +++--- .../windows_ad_gpo_new_cse_addition.yml | 6 +++--- .../endpoint/windows_ad_hidden_ou_creation.yml | 6 +++--- .../windows_ad_object_owner_updated.yml | 16 ++++++++-------- ...privileged_account_sid_history_addition.yml | 6 +++--- ...indows_ad_privileged_group_modification.yml | 6 +++--- .../windows_ad_self_dacl_assignment.yml | 18 +++++++++--------- .../endpoint/windows_ai_platform_dns_query.yml | 6 +++--- .../windows_applocker_block_events.yml | 6 +++--- ...lege_escalation_via_unauthorized_bypass.yml | 6 +++--- ...indows_attempt_to_stop_security_service.yml | 6 +++--- ...dows_defender_asr_registry_modification.yml | 6 +++--- .../windows_defender_asr_rule_disabled.yml | 6 +++--- .../windows_defender_asr_rules_stacking.yml | 6 +++--- ...search_order_hijacking_hunt_with_sysmon.yml | 6 +++--- ...ws_domain_admin_impersonation_indicator.yml | 6 +++--- ...dows_dotnet_binary_in_non_standard_path.yml | 8 ++++---- .../endpoint/windows_hosts_file_access.yml | 6 +++--- .../windows_identify_protocol_handlers.yml | 6 +++--- ...windows_important_audit_policy_disabled.yml | 6 +++--- ...windows_kerberos_local_successful_logon.yml | 6 +++--- .../windows_known_abused_dll_created.yml | 6 +++--- ...windows_lolbas_executed_as_renamed_file.yml | 6 +++--- ...s_lolbas_executed_outside_expected_path.yml | 8 ++++---- .../endpoint/windows_nirsoft_utilities.yml | 6 +++--- ...owershell_process_with_malicious_string.yml | 6 +++--- ...hell_script_block_with_malicious_string.yml | 6 +++--- detections/endpoint/windows_pua_named_pipe.yml | 6 +++--- detections/endpoint/windows_rmm_named_pipe.yml | 6 +++--- ..._scheduled_task_with_suspicious_command.yml | 6 +++--- ...ows_scheduled_task_with_suspicious_name.yml | 6 +++--- ...ce_created_with_suspicious_service_name.yml | 6 +++--- .../windows_suspicious_c2_named_pipe.yml | 6 +++--- .../endpoint/windows_suspicious_named_pipe.yml | 6 +++--- .../windows_vulnerable_driver_installed.yml | 6 +++--- .../windows_vulnerable_driver_loaded.yml | 6 +++--- ..._supply_chain_attack_network_indicators.yml | 6 +++--- ...re_firewall___binary_file_type_download.yml | 6 +++--- ...blacklisted_ssl_certificate_fingerprint.yml | 6 +++--- ...wall___file_download_over_uncommon_port.yml | 6 +++--- ...l___intrusion_events_by_threat_activity.yml | 8 ++++---- ...cure_firewall___malware_file_downloaded.yml | 6 +++--- ...___remote_access_software_usage_traffic.yml | 6 +++--- ...e_firewall___repeated_malware_downloads.yml | 6 +++--- ..._connecting_to_dynamic_domain_providers.yml | 8 ++++---- ...detect_remote_access_software_usage_dns.yml | 6 +++--- ...ct_remote_access_software_usage_traffic.yml | 6 +++--- .../network/http_c2_framework_user_agent.yml | 6 +++--- detections/network/http_malware_user_agent.yml | 6 +++--- detections/network/http_pua_user_agent.yml | 6 +++--- detections/network/http_rmm_user_agent.yml | 6 +++--- .../prohibited_network_traffic_allowed.yml | 6 +++--- ...detect_remote_access_software_usage_url.yml | 6 +++--- .../web/http_scripting_tool_user_agent.yml | 6 +++--- macros/base64decode.yml | 6 +++--- ...remote_access_software_usage_exceptions.yml | 6 +++--- macros/suspicious_writes.yml | 6 +++--- 92 files changed, 301 insertions(+), 301 deletions(-) diff --git a/detections/cloud/azure_ad_privileged_role_assigned.yml b/detections/cloud/azure_ad_privileged_role_assigned.yml index d352b47e158..29ccd68bf85 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned.yml @@ -1,8 +1,8 @@ name: Azure AD Privileged Role Assigned id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a -version: 16 +version: 17 creation_date: '2022-08-29' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk status: production type: TTP @@ -20,7 +20,7 @@ search: |- BY dest user src vendor_account vendor_product initiatedBy result role signature - | lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description + | lookup local=t privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description | search isprvilegedadrole = True | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml index 7064e4b1e2c..9640b9bc5d6 100644 --- a/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/azure_ad_privileged_role_assigned_to_service_principal.yml @@ -1,8 +1,8 @@ name: Azure AD Privileged Role Assigned to Service Principal id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41 -version: 14 +version: 15 creation_date: '2023-04-28' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Mauricio Velazco, Splunk status: production type: TTP @@ -24,7 +24,7 @@ search: |- vendor_account vendor_product displayName initiatedBy result role signature - | lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description + | lookup local=t privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description | search isprvilegedadrole = True | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/cloud/circle_ci_disable_security_job.yml b/detections/cloud/circle_ci_disable_security_job.yml index 86c52cf751c..22d5f050395 100644 --- a/detections/cloud/circle_ci_disable_security_job.yml +++ b/detections/cloud/circle_ci_disable_security_job.yml @@ -1,8 +1,8 @@ name: Circle CI Disable Security Job id: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 -version: 10 +version: 11 creation_date: '2021-09-02' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Patrick Bareiss, Splunk status: production type: Anomaly @@ -15,7 +15,7 @@ search: |- | stats values(job_name) as job_names BY workflow_id workflow_name user commit_message url branch - | lookup mandatory_job_for_workflow workflow_name OUTPUTNEW job_name AS mandatory_job + | lookup local=t mandatory_job_for_workflow workflow_name OUTPUTNEW job_name AS mandatory_job | search mandatory_job=* | eval mandatory_job_executed=if(like(job_names, "%".mandatory_job."%"), 1, 0) | where mandatory_job_executed=0 diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index eacd8e6352b..ddd55187d0a 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -1,8 +1,8 @@ name: Cloud API Calls From Previously Unseen User Roles id: 2181ad1f-1e73-4d0c-9780-e8880482a08f -version: 11 +version: 12 creation_date: '2020-10-27' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Splunk status: production type: Anomaly @@ -16,7 +16,7 @@ search: |- All_Changes.status=success BY All_Changes.user, All_Changes.command All_Changes.object | `drop_dm_object_name("All_Changes")` - | lookup previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenUserApiCall=min(firstTimeSeen) diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index c6b2f67045d..223a8926b2e 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -1,8 +1,8 @@ name: Cloud Compute Instance Created By Previously Unseen User id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 -version: 12 +version: 13 creation_date: '2019-10-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Splunk status: production type: Anomaly @@ -14,7 +14,7 @@ search: |- WHERE All_Changes.action=created BY All_Changes.user All_Changes.vendor_region | `drop_dm_object_name("All_Changes")` - | lookup previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenUser=min(firstTimeSeen) diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 1e909aad75e..9d8da86c8ea 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -1,8 +1,8 @@ name: Cloud Compute Instance Created In Previously Unused Region id: fa4089e2-50e3-40f7-8469-d2cc1564ca59 -version: 10 +version: 11 creation_date: '2020-11-30' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Splunk status: production type: Anomaly @@ -14,7 +14,7 @@ search: |- WHERE All_Changes.action=created BY All_Changes.vendor_region, All_Changes.user | `drop_dm_object_name("All_Changes")` - | lookup previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenRegion=min(firstTimeSeen) diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index acb3a1e5c8e..98bcc0d7b31 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -1,8 +1,8 @@ name: Cloud Compute Instance Created With Previously Unseen Image id: bc24922d-987c-4645-b288-f8c73ec194c4 -version: 10 +version: 11 creation_date: '2020-04-29' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Splunk status: production type: Anomaly @@ -16,7 +16,7 @@ search: |- | `drop_dm_object_name("All_Changes")` | `drop_dm_object_name("Instance_Changes")` | where image_id != "unknown" - | lookup previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenImage=min(firstTimeSeen) diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 3ff282b40bd..d6277404767 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -1,8 +1,8 @@ name: Cloud Compute Instance Created With Previously Unseen Instance Type id: c6ddbf53-9715-49f3-bb4c-fb2e8a309cda -version: 11 +version: 12 creation_date: '2019-10-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Splunk status: production type: Anomaly @@ -26,7 +26,7 @@ search: |- | `drop_dm_object_name("All_Changes")` | `drop_dm_object_name("Instance_Changes")` | where instance_type != "unknown" - | lookup previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenInstanceType=min(firstTimeSeen) diff --git a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml index 9a90486c1b6..2ff5d407c10 100644 --- a/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_by_previously_unseen_user.yml @@ -1,8 +1,8 @@ name: Cloud Instance Modified By Previously Unseen User id: 7fb15084-b14e-405a-bd61-a6de15a40722 -version: 12 +version: 13 creation_date: '2020-11-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Splunk status: production type: Anomaly @@ -14,7 +14,7 @@ search: |- WHERE All_Changes.action=modified All_Changes.change_type=EC2 All_Changes.status=success BY All_Changes.user | `drop_dm_object_name("All_Changes")` - | lookup previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenUser=min(firstTimeSeen) diff --git a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml index 19fb7fd7ce3..986561019d7 100644 --- a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_city.yml @@ -1,8 +1,8 @@ name: Cloud Provisioning Activity From Previously Unseen City id: e7ecc5e0-88df-48b9-91af-51104c68f02f -version: 9 +version: 10 creation_date: '2020-11-30' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Bhavin Patel, Splunk status: production type: Anomaly @@ -22,7 +22,7 @@ search: |- | `drop_dm_object_name("All_Changes")` | iplocation src | where isnotnull(City) - | lookup previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenCity=min(firstTimeSeen) diff --git a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml index b88a2410262..a59431fb49a 100644 --- a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_country.yml @@ -1,8 +1,8 @@ name: Cloud Provisioning Activity From Previously Unseen Country id: 94994255-3acf-4213-9b3f-0494df03bb31 -version: 9 +version: 10 creation_date: '2020-12-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Bhavin Patel, Splunk status: production type: Anomaly @@ -22,7 +22,7 @@ search: |- | `drop_dm_object_name("All_Changes")` | iplocation src | where isnotnull(Country) - | lookup previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenCountry=min(firstTimeSeen) diff --git a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml index c66d7cbe66a..94db84a678f 100644 --- a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_ip_address.yml @@ -1,8 +1,8 @@ name: Cloud Provisioning Activity From Previously Unseen IP Address id: f86a8ec9-b042-45eb-92f4-e9ed1d781078 -version: 9 +version: 10 creation_date: '2020-11-30' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Splunk status: production type: Anomaly @@ -19,7 +19,7 @@ search: |- All_Changes.status=success BY All_Changes.src, All_Changes.user, All_Changes.command | `drop_dm_object_name("All_Changes")` - | lookup previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenSrc=min(firstTimeSeen) diff --git a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml index 68b6adb810e..ecd39cf37de 100644 --- a/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_activity_from_previously_unseen_region.yml @@ -1,8 +1,8 @@ name: Cloud Provisioning Activity From Previously Unseen Region id: 5aba1860-9617-4af9-b19d-aecac16fe4f2 -version: 9 +version: 10 creation_date: '2020-10-26' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Bhavin Patel, Splunk status: production type: Anomaly @@ -22,7 +22,7 @@ search: |- | `drop_dm_object_name("All_Changes")` | iplocation src | where isnotnull(Region) - | lookup previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data + | lookup local=t previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data | eventstats max(enough_data) as enough_data | where enough_data=1 | eval firstTimeSeenRegion=min(firstTimeSeen) diff --git a/detections/cloud/kubernetes_nginx_ingress_lfi.yml b/detections/cloud/kubernetes_nginx_ingress_lfi.yml index 93c1f49678b..0cc3b3e3437 100644 --- a/detections/cloud/kubernetes_nginx_ingress_lfi.yml +++ b/detections/cloud/kubernetes_nginx_ingress_lfi.yml @@ -1,14 +1,14 @@ name: Kubernetes Nginx Ingress LFI id: 0f83244b-425b-4528-83db-7a88c5f66e48 -version: 11 +version: 12 creation_date: '2021-08-23' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Patrick Bareiss, Splunk status: production type: TTP description: The following analytic detects local file inclusion (LFI) attacks targeting Kubernetes Nginx ingress controllers. It leverages Kubernetes logs, parsing fields such as `request` and `status` to identify suspicious patterns indicative of LFI attempts. This activity is significant because LFI attacks can allow attackers to read sensitive files from the server, potentially exposing critical information. If confirmed malicious, this could lead to unauthorized access to sensitive data, further exploitation, and potential compromise of the Kubernetes environment. data_source: [] -search: '`kubernetes_container_controller` | rex field=_raw "^(?\S+)\s+-\s+-\s+\[(?[^\]]*)\]\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\"(?[^\"]*)\"\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\[(?[^\]]*)\]\s\[(?[^\]]*)\]\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)" | rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy | rex field=request "^(?\S+)\s(?\S+)\s" | eval phase="operate" | eval severity="high" | stats count min(_time) as firstTime max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent, proxy, phase, severity, request | lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT lfi_path | search lfi_path=yes | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `kubernetes_nginx_ingress_lfi_filter`' +search: '`kubernetes_container_controller` | rex field=_raw "^(?\S+)\s+-\s+-\s+\[(?[^\]]*)\]\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\"(?[^\"]*)\"\s\"(?[^\"]*)\"\s(?\S*)\s(?\S*)\s\[(?[^\]]*)\]\s\[(?[^\]]*)\]\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)\s(?\S*)" | rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name as proxy | rex field=request "^(?\S+)\s(?\S+)\s" | eval phase="operate" | eval severity="high" | stats count min(_time) as firstTime max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent, proxy, phase, severity, request | lookup local=t local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT lfi_path | search lfi_path=yes | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `kubernetes_nginx_ingress_lfi_filter`' how_to_implement: You must ingest Kubernetes logs through Splunk Connect for Kubernetes. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/cloud/o365_bec_email_hiding_rule_created.yml b/detections/cloud/o365_bec_email_hiding_rule_created.yml index 7887386766b..de038e494d2 100644 --- a/detections/cloud/o365_bec_email_hiding_rule_created.yml +++ b/detections/cloud/o365_bec_email_hiding_rule_created.yml @@ -1,8 +1,8 @@ name: O365 BEC Email Hiding Rule Created id: 603ebac2-f157-4df7-a6ac-34e8d0350f86 -version: 8 +version: 9 creation_date: '2025-02-14' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: '0xC0FFEEEE, Github Community' status: production type: TTP @@ -13,7 +13,7 @@ search: |- | stats min(_time) as firstTime, max(_time) as lastTime, values(Operation) as Operation, latest(Name) as Name, latest(MarkAsRead) as MarkAsRead, latest(MoveToFolder) as MoveToFolder by object_id user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup ut_shannon_lookup word as Name + | lookup local=t ut_shannon_lookup word as Name | eval entropy_score=if(ut_shannon<=2, 1, 0) | eval len_score=if(len(Name)<=3, 1,0) | eval read_score=if(MarkAsRead="True", 1, 0) diff --git a/detections/cloud/o365_privileged_role_assigned.yml b/detections/cloud/o365_privileged_role_assigned.yml index 75a8eaf3254..f4680f055fe 100644 --- a/detections/cloud/o365_privileged_role_assigned.yml +++ b/detections/cloud/o365_privileged_role_assigned.yml @@ -1,15 +1,15 @@ name: O365 Privileged Role Assigned id: db435700-4ddc-4c23-892e-49e7525d7d39 -version: 11 +version: 12 creation_date: '2024-04-13' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP description: The following analytic identifies the assignment of sensitive and privileged Azure Active Directory roles to an Azure AD user. Adversaries and red teams alike may assign these roles to a compromised account to establish Persistence in an Azure AD environment. This detection leverages the O365 Universal Audit Log data source. data_source: - Office 365 Universal Audit Log -search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2) | fillnull | stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature, vendor_account, vendor_product, dest | lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole | search isprvilegedadrole=\"TRUE\" category=\"User\" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_filter`" +search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2) | fillnull | stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature, vendor_account, vendor_product, dest | lookup local=t privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole | search isprvilegedadrole=\"TRUE\" category=\"User\" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_filter`" how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. known_false_positives: Administrators will legitimately assign the privileged roles users as part of administrative tasks. Microsoft Privileged Identity Management (PIM) may cause false positives / less accurate alerting. references: diff --git a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml index 3ccfbf7cbfd..ffeaa95712c 100644 --- a/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml +++ b/detections/cloud/o365_privileged_role_assigned_to_service_principal.yml @@ -1,15 +1,15 @@ name: O365 Privileged Role Assigned To Service Principal id: 80f3fc1b-705f-4080-bf08-f61bf013b900 -version: 11 +version: 12 creation_date: '2024-04-13' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP description: The following analytic detects potential privilege escalation threats in Azure Active Directory (AD). This detection is important because it identifies instances where privileged roles that hold elevated permissions are assigned to service principals. This prevents unauthorized access or malicious activities, which occur when these non-human entities access Azure resources to exploit them. False positives might occur since administrators can legitimately assign privileged roles to service principals. This detection leverages the O365 Universal Audit Log data source. data_source: - Office 365 Universal Audit Log -search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2) | fillnull | stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature,vendor_account, vendor_product, dest | lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole | search isprvilegedadrole=\"TRUE\" category!=\"User\" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_to_service_principal_filter`" +search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2) | fillnull | stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature,vendor_account, vendor_product, dest | lookup local=t privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole | search isprvilegedadrole=\"TRUE\" category!=\"User\" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_to_service_principal_filter`" how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. known_false_positives: Administrators may legitimately assign the privileged roles to Service Principals as part of administrative tasks. Filter as needed. references: diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 2f1379ec50a..57ab16b66d7 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,8 +1,8 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 19 +version: 20 creation_date: '2021-07-12' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Bhavin Patel, Splunk, sventec, Github Community status: production type: TTP @@ -42,7 +42,7 @@ search: |- | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup attacker_tools attacker_tool_names AS process_name OUTPUT description + | lookup local=t attacker_tools attacker_tool_names AS process_name OUTPUT description | search description !=false | `attacker_tools_on_endpoint_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml index 1230dc1fe34..842d16656fa 100644 --- a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Installation of Typosquatted Python Package id: 5e3f6b44-42cb-4f8a-99f0-59e78a52ea1d -version: 5 +version: 6 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -21,7 +21,7 @@ search: | (process_arguments = "*poetry*" process_arguments = "*add*") ) | rex field=process_arguments "(?i)(?:pip|poetry)[^|]*?\s+(?:install|add)\s+(?P[^\s\"']+)$" - | lookup typo_squatted_python_packages + | lookup local=t typo_squatted_python_packages typosquatted_package_name as package_name OUTPUTNEW comment package_official_url | where isnotnull(comment) diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml index 012a98db4fd..e59c8e2b07d 100644 --- a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Outbound Connection to Suspicious Port id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -33,7 +33,7 @@ search: | values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport - | lookup suspicious_ports_list dest_port OUTPUTNEW comment as dest_port_metadata confidence as dest_confidence category as dest_port_category + | lookup local=t suspicious_ports_list dest_port OUTPUTNEW comment as dest_port_metadata confidence as dest_confidence category as dest_port_category | where isnotnull(dest_port_metadata) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/detect_remote_access_software_usage_file.yml b/detections/endpoint/detect_remote_access_software_usage_file.yml index 6c971f45ac7..0746d33835a 100644 --- a/detections/endpoint/detect_remote_access_software_usage_file.yml +++ b/detections/endpoint/detect_remote_access_software_usage_file.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage File id: 3bf5541a-6a45-4fdc-b01d-59b899fff961 -version: 16 +version: 17 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -40,7 +40,7 @@ search: | | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Filesystem)` - | lookup remote_access_software remote_utility AS file_name OUTPUT isutility, description as signature, comment_reference as desc, category + | lookup local=t remote_access_software remote_utility AS file_name OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = TRUE | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_file_filter` diff --git a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml index 2c3579d0b6f..b7e8eb806bb 100644 --- a/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml +++ b/detections/endpoint/detect_remote_access_software_usage_fileinfo.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage FileInfo id: ccad96d7-a48c-4f13-8b9c-9f6a31cba454 -version: 15 +version: 16 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -19,7 +19,7 @@ search: |- process_hash process_id process_integrity_level process_name process_path user user_id vendor_product - | lookup remote_access_software remote_utility_fileinfo AS Product OUTPUT isutility, description as signature, comment_reference as desc, category + | lookup local=t remote_access_software remote_utility_fileinfo AS Product OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = True | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_fileinfo_filter` diff --git a/detections/endpoint/detect_remote_access_software_usage_process.yml b/detections/endpoint/detect_remote_access_software_usage_process.yml index 49afb5a4844..b80e1ec8b9d 100644 --- a/detections/endpoint/detect_remote_access_software_usage_process.yml +++ b/detections/endpoint/detect_remote_access_software_usage_process.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage Process id: ffd5e001-2e34-48f4-97a2-26dc4bb08178 -version: 17 +version: 18 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick, Sebastian Wurl, Splunk Community status: production type: Anomaly @@ -24,7 +24,7 @@ search: | | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` - | lookup remote_access_software remote_utility AS process_name OUTPUT isutility description AS signature comment_reference AS desc category + | lookup local=t remote_access_software remote_utility AS process_name OUTPUT isutility description AS signature comment_reference AS desc category | search isutility = TRUE | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_process_filter` diff --git a/detections/endpoint/detect_remote_access_software_usage_registry.yml b/detections/endpoint/detect_remote_access_software_usage_registry.yml index 3d9d5dfbde7..f000f5d3d43 100644 --- a/detections/endpoint/detect_remote_access_software_usage_registry.yml +++ b/detections/endpoint/detect_remote_access_software_usage_registry.yml @@ -1,15 +1,15 @@ name: Detect Remote Access Software Usage Registry id: 33804986-25dd-43cf-bb6b-dc14956c7cbc -version: 13 +version: 14 creation_date: '2024-12-28' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly description: The following analytic detects when a known remote access software is added to common persistence locations on a device within the environment. Adversaries use these utilities to retain remote access capabilities to the environment. Utilities in the lookup include AnyDesk, GoToMyPC, LogMeIn, TeamViewer and much more. Review the lookup for the entire list and add any others. data_source: - Sysmon EventID 13 -search: '| tstats `security_content_summariesonly` latest(Registry.process_guid) as process_guid count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Microsoft\\Windows\\CurrentVersion\\Run*" OR (Registry.registry_path="*\\SYSTEM\\CurrentControlSet\\Services\\*" AND Registry.registry_value_name="ImagePath")) by Registry.action Registry.dest Registry.process_guid Registry.process_id Registry.registry_hive Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.registry_value_name Registry.registry_value_type Registry.status Registry.user Registry.vendor_product | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | rex field=registry_value_data "(\")?.+\\\(?[^\"=]+\.[^\" ]{1,5})(\")?" | rex field=registry_value_data "(?[^\.]+\.[^\" ]{1,5}$)" | eval file_name = coalesce(file_name_1,file_name_2) | lookup remote_access_software remote_utility AS file_name OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = TRUE | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_registry_filter`' +search: '| tstats `security_content_summariesonly` latest(Registry.process_guid) as process_guid count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Microsoft\\Windows\\CurrentVersion\\Run*" OR (Registry.registry_path="*\\SYSTEM\\CurrentControlSet\\Services\\*" AND Registry.registry_value_name="ImagePath")) by Registry.action Registry.dest Registry.process_guid Registry.process_id Registry.registry_hive Registry.registry_path Registry.registry_key_name Registry.registry_value_data Registry.registry_value_name Registry.registry_value_type Registry.status Registry.user Registry.vendor_product | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | rex field=registry_value_data "(\")?.+\\\(?[^\"=]+\.[^\" ]{1,5})(\")?" | rex field=registry_value_data "(?[^\.]+\.[^\" ]{1,5}$)" | eval file_name = coalesce(file_name_1,file_name_2) | lookup local=t remote_access_software remote_utility AS file_name OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = TRUE | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_registry_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the file path, file name, and the user that created the file. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Registry` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. The "exceptions" macro leverages both an Assets and Identities lookup, as well as a KVStore collection called "remote_software_exceptions" that lets you track and maintain device-based exceptions for this set of detections. known_false_positives: Known or approved applications used by the organization or usage of built-in functions. Known false positives can be added to the remote_access_software_usage_exception.csv lookup to globally suppress these situations across all remote access content references: diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/endpoint/first_time_seen_child_process_of_zoom.yml index 6f88871ef26..3c4b132b750 100644 --- a/detections/endpoint/first_time_seen_child_process_of_zoom.yml +++ b/detections/endpoint/first_time_seen_child_process_of_zoom.yml @@ -1,8 +1,8 @@ name: First Time Seen Child Process of Zoom id: e91bd102-d630-4e76-ab73-7e3ba22c5961 -version: 11 +version: 12 creation_date: '2020-05-28' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -20,7 +20,7 @@ search: |- ) BY Processes.process_id Processes.dest | `drop_dm_object_name(Processes)` - | lookup zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen + | lookup local=t zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen | where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_zoom_child_processes_window`") | `security_content_ctime(firstTime)` | `first_time_seen_child_process_of_zoom_filter` diff --git a/detections/endpoint/potential_password_in_username.yml b/detections/endpoint/potential_password_in_username.yml index e6fb5a7cbe4..06649111165 100644 --- a/detections/endpoint/potential_password_in_username.yml +++ b/detections/endpoint/potential_password_in_username.yml @@ -1,8 +1,8 @@ name: Potential password in username id: 5ced34b4-ab32-4bb0-8f22-3b8f186f0a38 -version: 8 +version: 9 creation_date: '2022-05-27' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Mikael Bjerkeland, Splunk status: production type: Hunting @@ -14,7 +14,7 @@ search: |- WHERE nodename=Authentication.Failed_Authentication BY "Authentication.user" | `drop_dm_object_name(Authentication)` - | lookup ut_shannon_lookup word AS user + | lookup local=t ut_shannon_lookup word AS user | where ut_shannon>3 AND len(user)>=8 AND mvcount(src) == 1 | sort count, - ut_shannon | eval incorrect_cred=user diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 4404c793fdb..34973c0d0a6 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -1,8 +1,8 @@ name: System Processes Run From Unexpected Locations id: a34aae96-ccf8-4aef-952c-3ea21444444d -version: 17 +version: 18 creation_date: '2019-10-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: David Dorsey, Michael Haag, Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -35,7 +35,7 @@ search: | | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup update=true is_windows_system_file filename as process_name OUTPUT systemFile + | lookup local=t update=true is_windows_system_file filename as process_name OUTPUT systemFile | search systemFile=true | `system_processes_run_from_unexpected_locations_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml index 9d6cd43a91b..22272eb1e64 100644 --- a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml +++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml @@ -1,15 +1,15 @@ name: Windows AD AdminSDHolder ACL Modified id: 00d877c3-7b7b-443d-9562-6b231e2abab9 -version: 11 +version: 12 creation_date: '2022-11-15' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Mauricio Velazco, Dean Luxton, Splunk status: production type: TTP description: The following analytic detects modifications to the Access Control List (ACL) of the AdminSDHolder object in a Windows domain, specifically the addition of new rules. It leverages EventCode 5136 from the Security Event Log, focusing on changes to the nTSecurityDescriptor attribute. This activity is significant because the AdminSDHolder object secures privileged group members, and unauthorized changes can allow attackers to establish persistence and escalate privileges. If confirmed malicious, this could enable an attacker to control domain-level permissions, compromising the entire Active Directory environment. data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=container ObjectDN="CN=AdminSDHolder,CN=System*" | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUTNEW builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats min(_time) as _time values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(SubjectLogonId) as SubjectLogonId by ObjectClass ObjectDN src_user user | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN (*denied*,D,OD,XD) AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_adminsdholder_acl_modified_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=container ObjectDN="CN=AdminSDHolder,CN=System*" | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUTNEW builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats min(_time) as _time values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(SubjectLogonId) as SubjectLogonId by ObjectClass ObjectDN src_user user | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN (*denied*,D,OD,XD) AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_adminsdholder_acl_modified_filter`' how_to_implement: To successfully implement this search, you ned to be ingesting eventcode `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for the AdminSDHolder object in order to log modifications. known_false_positives: Adding new users or groups to the AdminSDHolder ACL is not usual. Filter as needed references: diff --git a/detections/endpoint/windows_ad_dangerous_deny_acl_modification.yml b/detections/endpoint/windows_ad_dangerous_deny_acl_modification.yml index 4c843d442b4..2ec0999809b 100644 --- a/detections/endpoint/windows_ad_dangerous_deny_acl_modification.yml +++ b/detections/endpoint/windows_ad_dangerous_deny_acl_modification.yml @@ -1,15 +1,15 @@ name: Windows AD Dangerous Deny ACL Modification id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: This detection identifies an Active Directory access-control list (ACL) modification event, which applies permissions that deny the ability to enumerate permissions of the object. data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search aceType IN ("Access denied",D) AND aceAccessRights IN ("Full control","Read permissions",RC) | `windows_ad_dangerous_deny_acl_modification_filter`' +search: '`wineventlog_security` EventCode=5136 | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search aceType IN ("Access denied",D) AND aceAccessRights IN ("Full control","Read permissions",RC) | `windows_ad_dangerous_deny_acl_modification_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_dangerous_group_acl_modification.yml b/detections/endpoint/windows_ad_dangerous_group_acl_modification.yml index 496738c80c9..bb3d90f6285 100644 --- a/detections/endpoint/windows_ad_dangerous_group_acl_modification.yml +++ b/detections/endpoint/windows_ad_dangerous_group_acl_modification.yml @@ -1,15 +1,15 @@ name: Windows AD Dangerous Group ACL Modification id: 59b0fc85-7a0d-4585-97ec-06a382801990 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: 'This detection monitors the addition of the following ACLs to an Active Directory group object: "Full control", "All extended rights", "All validated writes", "Create all child objects", "Delete all child objects", "Delete subtree", "Delete", "Modify permissions", "Modify owner", and "Write all properties". Such modifications can indicate potential privilege escalation or malicious activity. Immediate investigation is recommended upon alert.' data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=group | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceInheritance=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=if((ControlAccessRights="Write member" OR aceObjectGuid="bf9679c0-0de6-11d0-a285-00aa003049e2") AND (aceAccessRights="All validated writes" OR AccessRights="SW"),"Add/remove self as member",coalesce(ControlAccessRights,aceObjectGuid)), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceInheritance) as aceInheritance values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN ("*denied*","D","OD","XD") AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_dangerous_group_acl_modification_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=group | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceInheritance=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=if((ControlAccessRights="Write member" OR aceObjectGuid="bf9679c0-0de6-11d0-a285-00aa003049e2") AND (aceAccessRights="All validated writes" OR AccessRights="SW"),"Add/remove self as member",coalesce(ControlAccessRights,aceObjectGuid)), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceInheritance) as aceInheritance values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN ("*denied*","D","OD","XD") AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_dangerous_group_acl_modification_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_dangerous_user_acl_modification.yml b/detections/endpoint/windows_ad_dangerous_user_acl_modification.yml index 953f11c0280..efaba46b0d9 100644 --- a/detections/endpoint/windows_ad_dangerous_user_acl_modification.yml +++ b/detections/endpoint/windows_ad_dangerous_user_acl_modification.yml @@ -1,15 +1,15 @@ name: Windows AD Dangerous User ACL Modification id: ec5b6790-595a-4fb8-ad43-56e5b55a9617 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: 'This detection monitors the addition of the following ACLs to an Active Directory user object: "Full control","All extended rights","All validated writes", "Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties". Such modifications can indicate potential privilege escalation or malicious activity. Immediate investigation is recommended upon alert.' data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=user | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN (*denied*,D,OD,XD) AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_dangerous_user_acl_modification_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=user | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search NOT aceType IN (*denied*,D,OD,XD) AND aceAccessRights IN ("Full control","All extended rights","All validated writes","Create all child objects","Delete all child objects","Delete subtree","Delete","Modify permissions","Modify owner","Write all properties",CC,CR,DC,DT,SD,SW,WD,WO,WP) | `windows_ad_dangerous_user_acl_modification_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_dcshadow_privileges_acl_addition.yml b/detections/endpoint/windows_ad_dcshadow_privileges_acl_addition.yml index 961b49dc716..6722e417c57 100644 --- a/detections/endpoint/windows_ad_dcshadow_privileges_acl_addition.yml +++ b/detections/endpoint/windows_ad_dcshadow_privileges_acl_addition.yml @@ -1,8 +1,8 @@ name: Windows AD DCShadow Privileges ACL Addition id: ae915743-1aa8-4a94-975c-8062ebc8b723 -version: 11 +version: 12 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -22,13 +22,13 @@ search: |- | search aceObjectGuid IN ("9923a32a-3607-11d2-b9be-0000f87a36b2","1131f6ab-9c07-11d1-f79f-00c04fc2dcd2","1131f6ac-9c07-11d1-f79f-00c04fc2dcd2") | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" - | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights - | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value - | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value - | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups - | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user - | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` - | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group + | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights + | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value + | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value + | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups + | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user + | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` + | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats min(_time) as _time values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(SubjectLogonId) as SubjectLogonId BY ObjectClass ObjectDN src_user diff --git a/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml b/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml index a9de68376c1..4ae8bbf8237 100644 --- a/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml +++ b/detections/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml @@ -1,8 +1,8 @@ name: Windows AD Domain Controller Audit Policy Disabled id: fc3ccef1-60a4-4239-bd66-b279511b4d14 -version: 12 +version: 13 creation_date: '2023-01-25' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -15,7 +15,7 @@ search: |- | eval AuditPolicyChanges=coalesce(AuditPolicyChanges,Changes), SubcategoryGuid=coalesce(SubcategoryGuid,Subcategory_GUID) | stats min(_time) as _time values(host) as dest BY AuditPolicyChanges SubcategoryGuid - | lookup advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory + | lookup local=t advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory | `windows_ad_domain_controller_audit_policy_disabled_filter` how_to_implement: Ensure you are ingesting EventCode `4719` from your domain controllers, the category domain_controller exists in assets and identities, and that assets and identities is enabled. If A&I is not configured, you will need to manually filter the results within the base search. known_false_positives: No false positives have been identified at this time. diff --git a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml index fa3da3a0fa4..008078814aa 100644 --- a/detections/endpoint/windows_ad_domain_replication_acl_addition.yml +++ b/detections/endpoint/windows_ad_domain_replication_acl_addition.yml @@ -1,8 +1,8 @@ name: Windows AD Domain Replication ACL Addition id: 8c372853-f459-4995-afdc-280c114d33ab -version: 14 +version: 15 creation_date: '2022-11-17' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -22,11 +22,11 @@ search: |- | search aceObjectGuid IN ("1131f6aa-9c07-11d1-f79f-00c04fc2dcd2","1131f6ad-9c07-11d1-f79f-00c04fc2dcd2","89e95b76-444d-4c62-991a-0facbeda640c") | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" - | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights - | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value - | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value - | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value - | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group + | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights + | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value + | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value + | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value + | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats min(_time) as _time values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(SubjectLogonId) as SubjectLogonId BY ObjectClass ObjectDN src_user dest user diff --git a/detections/endpoint/windows_ad_domain_root_acl_deletion.yml b/detections/endpoint/windows_ad_domain_root_acl_deletion.yml index 3d8f5ea920b..f4c529ed511 100644 --- a/detections/endpoint/windows_ad_domain_root_acl_deletion.yml +++ b/detections/endpoint/windows_ad_domain_root_acl_deletion.yml @@ -1,15 +1,15 @@ name: Windows AD Domain Root ACL Deletion id: 3cb56e57-5642-4638-907f-8dfde9afb889 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: ACL deletion performed on the domain root object, significant AD change with high impact. Following MS guidance all changes at this level should be reviewed. Drill into the logonID within EventCode 4624 for information on the source device during triage. data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=domainDNS | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand old_values | where NOT old_values IN (new_values) | rex field=old_values "(?P.*?);(?P.*?);(?P.*?);(?P.*?);;(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(old_values) as old_values by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | `windows_ad_domain_root_acl_deletion_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=domainDNS | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand old_values | where NOT old_values IN (new_values) | rex field=old_values "(?P.*?);(?P.*?);(?P.*?);(?P.*?);;(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(old_values) as old_values by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | `windows_ad_domain_root_acl_deletion_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_domain_root_acl_modification.yml b/detections/endpoint/windows_ad_domain_root_acl_modification.yml index dd7f05a1ec1..e3e9320ce78 100644 --- a/detections/endpoint/windows_ad_domain_root_acl_modification.yml +++ b/detections/endpoint/windows_ad_domain_root_acl_modification.yml @@ -1,15 +1,15 @@ name: Windows AD Domain Root ACL Modification id: 4981e2db-1372-440d-816e-3e7e2ed74433 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: ACL modification performed on the domain root object, significant AD change with high impact. Following MS guidance all changes at this level should be reviewed. Drill into the logonID within EventCode 4624 for information on the source device during triage. data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=domainDNS | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);;(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",''access_rights_value''), aceType=ace_type_value, aceFlags=coalesce(ace_flag_value,"This object only"), aceControlAccessRights=ControlAccessRights, user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | `windows_ad_domain_root_acl_modification_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=domainDNS | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);;(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",''access_rights_value''), aceType=ace_type_value, aceFlags=coalesce(ace_flag_value,"This object only"), aceControlAccessRights=ControlAccessRights, user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags(inheritance) values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | `windows_ad_domain_root_acl_modification_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_gpo_new_cse_addition.yml b/detections/endpoint/windows_ad_gpo_new_cse_addition.yml index ee01fe92ecd..7ee0d8c86b5 100644 --- a/detections/endpoint/windows_ad_gpo_new_cse_addition.yml +++ b/detections/endpoint/windows_ad_gpo_new_cse_addition.yml @@ -1,8 +1,8 @@ name: Windows AD GPO New CSE Addition id: 700c11d1-da09-47b2-81aa-358c143c7986 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -24,7 +24,7 @@ search: |- | \d]+\-[A-Z | \d]+\-[A-Z | \d]+\}") - | lookup msad_guid_lookup guid as new_values OUTPUTNEW displayName as policyType + | lookup local=t msad_guid_lookup guid as new_values OUTPUTNEW displayName as policyType | eval newPolicy=if(policyType like "%",policyType,new_values) | join ObjectDN [ | search `admon` objectCategory="CN=Group-Policy-Container*" admonEventType=Update diff --git a/detections/endpoint/windows_ad_hidden_ou_creation.yml b/detections/endpoint/windows_ad_hidden_ou_creation.yml index 753e9958033..f3b1f2b8cc0 100644 --- a/detections/endpoint/windows_ad_hidden_ou_creation.yml +++ b/detections/endpoint/windows_ad_hidden_ou_creation.yml @@ -1,15 +1,15 @@ name: Windows AD Hidden OU Creation id: 66b6ad5e-339a-40af-b721-dacefc7bdb75 -version: 10 +version: 11 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP description: This analytic is looking for when an ACL is applied to an OU which denies listing the objects residing in the OU. This activity combined with modifying the owner of the OU will hide AD objects even from domain administrators. data_source: - Windows Event Log Security 5136 -search: '`wineventlog_security` EventCode=5136 ObjectClass=organizationalUnit | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search aceType IN ("Access denied",D) AND aceAccessRights IN ("List contents","List objects",LC,LO) | `windows_ad_hidden_ou_creation_filter`' +search: '`wineventlog_security` EventCode=5136 ObjectClass=organizationalUnit | stats min(_time) as _time values(eval(if(OperationType=="%%14675",AttributeValue,null))) as old_value values(eval(if(OperationType=="%%14674",AttributeValue,null))) as new_value values(OperationType) as OperationType values(dest) as dest by ObjectClass ObjectDN OpCorrelationID src_user SubjectLogonId | rex field=old_value max_match=10000 "\((?P.*?)\)" | rex field=new_value max_match=10000 "\((?P.*?)\)" | mvexpand new_ace | where NOT new_ace IN (old_values) | rex field=new_ace "(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?);(?P.*?)$" | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value ``` Optional SID resolution lookups | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType=coalesce(ace_type_value,aceType), aceFlags=coalesce(ace_flag_value,"This object only"), aceAccessRights=if(aceAccessRights="CCDCLCSWRPWPDTLOCRSDRCWDWO","Full control",coalesce(access_rights_value,AccessRights)), aceControlAccessRights=coalesce(ControlAccessRights,aceObjectGuid), user=coalesce(user, group, builtin_group, aceSid) | stats values(aceType) as aceType values(aceFlags) as aceFlags values(aceControlAccessRights) as aceControlAccessRights values(aceAccessRights) as aceAccessRights values(new_ace) as new_ace values(aceInheritedTypeGuid) as aceInheritedTypeGuid by _time ObjectClass ObjectDN src_user SubjectLogonId user OpCorrelationID | eval aceControlAccessRights=if(mvcount(aceControlAccessRights)=1 AND aceControlAccessRights="","All rights",''aceControlAccessRights'') | search aceType IN ("Access denied",D) AND aceAccessRights IN ("List contents","List objects",LC,LO) | `windows_ad_hidden_ou_creation_filter`' how_to_implement: Ensure you are ingesting Active Directory audit logs - specifically event 5136. See lantern article in references for further on how to onboard AD audit data. Ensure the wineventlog_security macro is configured with the correct indexes and include lookups for SID resolution if evt_resolve_ad_obj is set to 0. known_false_positives: No false positives have been identified at this time. references: diff --git a/detections/endpoint/windows_ad_object_owner_updated.yml b/detections/endpoint/windows_ad_object_owner_updated.yml index b242e6adefb..d26cae513be 100644 --- a/detections/endpoint/windows_ad_object_owner_updated.yml +++ b/detections/endpoint/windows_ad_object_owner_updated.yml @@ -1,8 +1,8 @@ name: Windows AD Object Owner Updated id: 4af01f6b-d8d4-4f96-8635-758a01557130 -version: 12 +version: 13 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -17,12 +17,12 @@ search: |- | rex field=old_value "O:(?P.*?)G:" | rex field=new_value "O:(?P.*?)G:" | where old_owner!=new_owner ``` optional SID resolution lookups - | lookup identity_lookup_expanded objectSid as new_owner OUTPUT downLevelDomainName as new_owner_user - | lookup admon_groups_def objectSid as new_owner OUTPUT cn as new_owner_group - | lookup identity_lookup_expanded objectSid as old_owner OUTPUT downLevelDomainName as old_owner_user - | lookup admon_groups_def objectSid as old_owner OUTPUT cn as old_owner_group ``` - | lookup builtin_groups_lookup builtin_group_string as new_owner_group OUTPUT builtin_group_name as new_owner_group_builtin_group - | lookup builtin_groups_lookup builtin_group_string as old_owner OUTPUT builtin_group_name as old_owner_group_builtin_group + | lookup local=t identity_lookup_expanded objectSid as new_owner OUTPUT downLevelDomainName as new_owner_user + | lookup local=t admon_groups_def objectSid as new_owner OUTPUT cn as new_owner_group + | lookup local=t identity_lookup_expanded objectSid as old_owner OUTPUT downLevelDomainName as old_owner_user + | lookup local=t admon_groups_def objectSid as old_owner OUTPUT cn as old_owner_group ``` + | lookup local=t builtin_groups_lookup builtin_group_string as new_owner_group OUTPUT builtin_group_name as new_owner_group_builtin_group + | lookup local=t builtin_groups_lookup builtin_group_string as old_owner OUTPUT builtin_group_name as old_owner_group_builtin_group | eval user=coalesce(new_owner_user, new_owner_group, new_owner_group_builtin_group, new_owner), previousOwner=coalesce(old_owner_user, old_owner_group, old_owner_group_builtin_group, old_owner) | stats values(previousOwner) as previousOwner values(user) as user values(SubjectLogonId) as SubjectLogonId BY _time ObjectClass ObjectDN diff --git a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml index 49124a77138..4d065865c8f 100644 --- a/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml +++ b/detections/endpoint/windows_ad_privileged_account_sid_history_addition.yml @@ -1,8 +1,8 @@ name: Windows AD Privileged Account SID History Addition id: 6b521149-b91c-43aa-ba97-c2cac59ec830 -version: 13 +version: 14 creation_date: '2023-04-11' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -16,7 +16,7 @@ search: |- NOT SidHistory IN ("%%1793", -) | rex field=SidHistory "(^%{|^)(?P.*?)(}$|$)" | eval category="privileged" - | lookup identity_lookup_expanded category, identity as SidHistory OUTPUT identity_tag as match + | lookup local=t identity_lookup_expanded category, identity as SidHistory OUTPUT identity_tag as match | where isnotnull(match) | rename TargetSid as userSid | table _time action status host user userSid SidHistory Logon_ID src_user dest diff --git a/detections/endpoint/windows_ad_privileged_group_modification.yml b/detections/endpoint/windows_ad_privileged_group_modification.yml index bcfe2f7cef9..0feccfdd2fb 100644 --- a/detections/endpoint/windows_ad_privileged_group_modification.yml +++ b/detections/endpoint/windows_ad_privileged_group_modification.yml @@ -1,8 +1,8 @@ name: Windows AD Privileged Group Modification id: 187bf937-c436-4c65-bbcb-7539ffe02da1 -version: 11 +version: 12 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -20,7 +20,7 @@ search: |- `wineventlog_security` EventCode IN (4728) | stats min(_time) as _time dc(user) as usercount, values(user) as user values(user_category) as user_category values(src_user_category) as src_user_category values(dvc) as dvc BY signature, Group_Name,src_user dest - | lookup admon_groups_def cn as Group_Name OUTPUT category + | lookup local=t admon_groups_def cn as Group_Name OUTPUT category | where category="privileged" | `windows_ad_privileged_group_modification_filter` how_to_implement: This analytic requires eventCode 4728 to be ingested along with the admon_groups_def lookup being configured to include a list of AD groups along with a category to identify privileged groups. See splunkbase app listed in the references for further details. diff --git a/detections/endpoint/windows_ad_self_dacl_assignment.yml b/detections/endpoint/windows_ad_self_dacl_assignment.yml index 086f99486a4..cc4b4578cdd 100644 --- a/detections/endpoint/windows_ad_self_dacl_assignment.yml +++ b/detections/endpoint/windows_ad_self_dacl_assignment.yml @@ -1,8 +1,8 @@ name: Windows AD Self DACL Assignment id: 16132445-da9f-4d03-ad44-56d717dcd67d -version: 12 +version: 13 creation_date: '2024-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -36,17 +36,17 @@ search: | | rex max_match=100 field=aceAccessRights "(?P[A-Z]{2})" | rex max_match=100 field=aceFlags "(?P[A-Z]{2})" - | lookup ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType - | lookup ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value - | lookup ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value - | lookup msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights + | lookup local=t ace_type_lookup ace_type_string as aceType OUTPUT ace_type_value as aceType + | lookup local=t ace_flag_lookup flag_string as aceFlags OUTPUT flag_value as ace_flag_value + | lookup local=t ace_access_rights_lookup access_rights_string as AccessRights OUTPUT access_rights_value + | lookup local=t msad_guid_lookup guid as aceObjectGuid OUTPUT displayName as ControlAccessRights ``` Optional SID resolution lookups - | lookup identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user - | lookup admon_groups_def objectSid as aceSid OUTPUT cn as group + | lookup local=t identity_lookup_expanded objectSid as aceSid OUTPUT downLevelDomainName as user + | lookup local=t admon_groups_def objectSid as aceSid OUTPUT cn as group ``` - | lookup builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group + | lookup local=t builtin_groups_lookup builtin_group_string as aceSid OUTPUT builtin_group_name as builtin_group | eval aceType = coalesce(ace_type_value, aceType), aceInheritance = coalesce(ace_flag_value, "This object only"), diff --git a/detections/endpoint/windows_ai_platform_dns_query.yml b/detections/endpoint/windows_ai_platform_dns_query.yml index 60a3555327e..64febb1b456 100644 --- a/detections/endpoint/windows_ai_platform_dns_query.yml +++ b/detections/endpoint/windows_ai_platform_dns_query.yml @@ -1,8 +1,8 @@ name: Windows AI Platform DNS Query id: 1ad89d24-c856-4a0e-8fdf-c20c7b9febe1 -version: 6 +version: 7 creation_date: '2025-08-28' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: - Sysmon EventID 22 search: | `sysmon` EventCode=22 QueryName IN ("router.huggingface.co", "api.openai.com") - | lookup update=true browser_app_list browser_process_name AS process_name OUTPUT isAllowed | search isAllowed!=true + | lookup local=t update=true browser_app_list browser_process_name AS process_name OUTPUT isAllowed | search isAllowed!=true | rename dvc as dest | stats count min(_time) as firstTime max(_time) as lastTime by answer answer_count dest process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id Image diff --git a/detections/endpoint/windows_applocker_block_events.yml b/detections/endpoint/windows_applocker_block_events.yml index 35ba239a3ba..e6acb3d585c 100644 --- a/detections/endpoint/windows_applocker_block_events.yml +++ b/detections/endpoint/windows_applocker_block_events.yml @@ -1,8 +1,8 @@ name: Windows AppLocker Block Events id: e369afe8-cd35-47a3-9c1e-d813efc1f7dd -version: 10 +version: 11 creation_date: '2024-04-17' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Anomaly @@ -16,7 +16,7 @@ search: |- BY dest, PolicyName, RuleId, user, TargetProcessId, FilePath, FullFilePath, EventCode - | lookup applockereventcodes EventCode OUTPUT Description + | lookup local=t applockereventcodes EventCode OUTPUT Description | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_applocker_block_events_filter` diff --git a/detections/endpoint/windows_applocker_privilege_escalation_via_unauthorized_bypass.yml b/detections/endpoint/windows_applocker_privilege_escalation_via_unauthorized_bypass.yml index 0af315282ff..15e389f0588 100644 --- a/detections/endpoint/windows_applocker_privilege_escalation_via_unauthorized_bypass.yml +++ b/detections/endpoint/windows_applocker_privilege_escalation_via_unauthorized_bypass.yml @@ -1,8 +1,8 @@ name: Windows AppLocker Privilege Escalation via Unauthorized Bypass id: bca48629-7fa2-40d3-9e5d-807564504e28 -version: 9 +version: 10 creation_date: '2024-04-17' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: TTP @@ -18,7 +18,7 @@ search: |- FullFilePath, EventCode | where attempt_count > 5 | sort - attempt_count - | lookup applockereventcodes EventCode OUTPUT Description + | lookup local=t applockereventcodes EventCode OUTPUT Description | `windows_applocker_privilege_escalation_via_unauthorized_bypass_filter` how_to_implement: The analytic is designed to be run against Windows AppLocker event logs collected from endpoints with AppLocker enabled. If using Microsoft Defender for Endpoint (MDE), modify the analytic to use EventTypes/ActionTypes that match the block events for AppLocker. The analytic requires the AppLocker event logs to be ingested into Splunk. known_false_positives: False positives are possible if legitimate users are attempting to bypass application restrictions. This could occur if a user is attempting to run an application that is not permitted by AppLocker. It is recommended to investigate the context of the bypass attempt to determine if it is malicious or not. Modify the threshold as needed to reduce false positives. diff --git a/detections/endpoint/windows_attempt_to_stop_security_service.yml b/detections/endpoint/windows_attempt_to_stop_security_service.yml index c5c5036f1fc..a0612d605f6 100644 --- a/detections/endpoint/windows_attempt_to_stop_security_service.yml +++ b/detections/endpoint/windows_attempt_to_stop_security_service.yml @@ -1,8 +1,8 @@ name: Windows Attempt To Stop Security Service id: 9ed27cea-4e27-4eff-b2c6-aac9e78a7517 -version: 11 +version: 12 creation_date: '2020-04-29' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Rico Valdez, Nasreddine Bencherchali, Splunk status: production type: TTP @@ -29,7 +29,7 @@ search: |- | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup security_services_lookup service as process OUTPUTNEW category, description + | lookup local=t security_services_lookup service as process OUTPUTNEW category, description | search category=security | `windows_attempt_to_stop_security_service_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/windows_defender_asr_registry_modification.yml b/detections/endpoint/windows_defender_asr_registry_modification.yml index 627268ebe1b..06c4bbcb8bb 100644 --- a/detections/endpoint/windows_defender_asr_registry_modification.yml +++ b/detections/endpoint/windows_defender_asr_registry_modification.yml @@ -1,15 +1,15 @@ name: Windows Defender ASR Registry Modification id: 6a1b6cbe-6612-44c3-92b9-1a1bd77412eb -version: 8 +version: 9 creation_date: '2023-12-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting description: The following analytic detects modifications to Windows Defender Attack Surface Reduction (ASR) registry settings. It leverages Windows Defender Operational logs, specifically EventCode 5007, to identify changes in ASR rules. This activity is significant because ASR rules are designed to block actions commonly used by malware to exploit systems. Unauthorized modifications to these settings could indicate an attempt to weaken system defenses. If confirmed malicious, this could allow an attacker to bypass security measures, leading to potential system compromise and data breaches. data_source: - Windows Event Log Defender 5007 -search: '`ms_defender` EventCode IN (5007) | rex field=New_Value "0x(?\\d+)$" | rex field=Old_Value "0x(?\\d+)$" | rex field=New_Value "Rules\\\\(?[A-Fa-f0-9\\-]+)\\s*=" | eval New_Registry_Value=case(New_Registry_Value=="0", "Disabled", New_Registry_Value=="1", "Block", New_Registry_Value=="2", "Audit", New_Registry_Value=="6", "Warn") | eval Old_Registry_Value=case(Old_Registry_Value=="0", "Disabled", Old_Registry_Value=="1", "Block", Old_Registry_Value=="2", "Audit", Old_Registry_Value=="6", "Warn") | stats count min(_time) as firstTime max(_time) as lastTime by host, New_Value, Old_Value, Old_Registry_Value, New_Registry_Value, ASR_ID | lookup asr_rules ID AS ASR_ID OUTPUT ASR_Rule | `security_content_ctime(firstTime)`| rename host as dest | `security_content_ctime(lastTime)` | `windows_defender_asr_registry_modification_filter`' +search: '`ms_defender` EventCode IN (5007) | rex field=New_Value "0x(?\\d+)$" | rex field=Old_Value "0x(?\\d+)$" | rex field=New_Value "Rules\\\\(?[A-Fa-f0-9\\-]+)\\s*=" | eval New_Registry_Value=case(New_Registry_Value=="0", "Disabled", New_Registry_Value=="1", "Block", New_Registry_Value=="2", "Audit", New_Registry_Value=="6", "Warn") | eval Old_Registry_Value=case(Old_Registry_Value=="0", "Disabled", Old_Registry_Value=="1", "Block", Old_Registry_Value=="2", "Audit", Old_Registry_Value=="6", "Warn") | stats count min(_time) as firstTime max(_time) as lastTime by host, New_Value, Old_Value, Old_Registry_Value, New_Registry_Value, ASR_ID | lookup local=t asr_rules ID AS ASR_ID OUTPUT ASR_Rule | `security_content_ctime(firstTime)`| rename host as dest | `security_content_ctime(lastTime)` | `windows_defender_asr_registry_modification_filter`' how_to_implement: The following analytic requires collection of Windows Defender Operational logs in either XML or multi-line. To collect, setup a new input for the Windows Defender Operational logs. In addition, it does require a lookup that maps the ID to ASR Rule name. known_false_positives: False positives are expected from legitimate applications generating events that are similar to those generated by malicious activity. For example, Event ID 5007 is generated when a process attempts to modify a registry key that is related to ASR rules. This can be triggered by legitimate applications that attempt to modify registry keys that are not blocked by ASR rules. references: diff --git a/detections/endpoint/windows_defender_asr_rule_disabled.yml b/detections/endpoint/windows_defender_asr_rule_disabled.yml index 29f4af1a665..eed3e8b8c5f 100644 --- a/detections/endpoint/windows_defender_asr_rule_disabled.yml +++ b/detections/endpoint/windows_defender_asr_rule_disabled.yml @@ -1,15 +1,15 @@ name: Windows Defender ASR Rule Disabled id: 429d611b-3183-49a7-b235-fc4203c4e1cb -version: 10 +version: 11 creation_date: '2023-12-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: TTP description: The following analytic identifies when a Windows Defender ASR rule disabled events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. ASR rules are applied to processes and applications. When a process or application attempts to perform an action that is blocked by an ASR rule, an event is generated. This detection searches for ASR rule disabled events that are generated when an ASR rule is disabled. data_source: - Windows Event Log Defender 5007 -search: '`ms_defender` EventCode IN (5007) | rex field=New_Value "0x(?\\d+)$" | rex field=Old_Value "0x(?\\d+)$" | rex field=New_Value "Rules\\\\(?[A-Fa-f0-9\\-]+)\\s*=" | eval New_Registry_Value=case(New_Registry_Value=="0", "Disabled", New_Registry_Value=="1", "Block", New_Registry_Value=="2", "Audit", New_Registry_Value=="6", "Warn") | eval Old_Registry_Value=case(Old_Registry_Value=="0", "Disabled", Old_Registry_Value=="1", "Block", Old_Registry_Value=="2", "Audit", Old_Registry_Value=="6", "Warn") | search New_Registry_Value="Disabled" | stats count min(_time) as firstTime max(_time) as lastTime by host, New_Value, Old_Value, Old_Registry_Value, New_Registry_Value, ASR_ID | lookup asr_rules ID AS ASR_ID OUTPUT ASR_Rule | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| rename host as dest | `windows_defender_asr_rule_disabled_filter`' +search: '`ms_defender` EventCode IN (5007) | rex field=New_Value "0x(?\\d+)$" | rex field=Old_Value "0x(?\\d+)$" | rex field=New_Value "Rules\\\\(?[A-Fa-f0-9\\-]+)\\s*=" | eval New_Registry_Value=case(New_Registry_Value=="0", "Disabled", New_Registry_Value=="1", "Block", New_Registry_Value=="2", "Audit", New_Registry_Value=="6", "Warn") | eval Old_Registry_Value=case(Old_Registry_Value=="0", "Disabled", Old_Registry_Value=="1", "Block", Old_Registry_Value=="2", "Audit", Old_Registry_Value=="6", "Warn") | search New_Registry_Value="Disabled" | stats count min(_time) as firstTime max(_time) as lastTime by host, New_Value, Old_Value, Old_Registry_Value, New_Registry_Value, ASR_ID | lookup local=t asr_rules ID AS ASR_ID OUTPUT ASR_Rule | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| rename host as dest | `windows_defender_asr_rule_disabled_filter`' how_to_implement: The following analytic requires collection of Windows Defender Operational logs in either XML or multi-line. To collect, setup a new input for the Windows Defender Operational logs. In addition, it does require a lookup that maps the ID to ASR Rule name. known_false_positives: False positives may occur if applications are typically disabling ASR rules in the environment. Monitor for changes to ASR rules to determine if this is a false positive. references: diff --git a/detections/endpoint/windows_defender_asr_rules_stacking.yml b/detections/endpoint/windows_defender_asr_rules_stacking.yml index 780f6b19932..1f0d5b29282 100644 --- a/detections/endpoint/windows_defender_asr_rules_stacking.yml +++ b/detections/endpoint/windows_defender_asr_rules_stacking.yml @@ -1,8 +1,8 @@ name: Windows Defender ASR Rules Stacking id: 425a6657-c5e4-4cbb-909e-fc9e5d326f01 -version: 8 +version: 9 creation_date: '2023-12-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting @@ -22,7 +22,7 @@ search: |- | stats count min(_time) as firstTime max(_time) as lastTime BY host Parent_Commandline, Process_Name, Path, ID, EventCode - | lookup asr_rules ID OUTPUT ASR_Rule + | lookup local=t asr_rules ID OUTPUT ASR_Rule | fillnull value=NULL | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml index ce9a6ee9814..f151287086b 100644 --- a/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml +++ b/detections/endpoint/windows_dll_search_order_hijacking_hunt_with_sysmon.yml @@ -1,15 +1,15 @@ name: Windows DLL Search Order Hijacking Hunt with Sysmon id: 79c7d1fc-64c7-91be-a616-ccda752efe81 -version: 12 +version: 13 creation_date: '2022-08-19' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting description: The following analytic identifies potential DLL search order hijacking or DLL sideloading by detecting known Windows libraries loaded from non-standard directories. It leverages Sysmon EventCode 7 to monitor DLL loads and cross-references them with a lookup of known hijackable libraries. This activity is significant as it may indicate an attempt to execute malicious code by exploiting DLL search order vulnerabilities. If confirmed malicious, this could allow attackers to gain code execution, escalate privileges, or maintain persistence within the environment. data_source: - Sysmon EventID 7 -search: '`sysmon` EventCode=7 NOT (process_path IN ("*\\system32\\*", "*\\syswow64\\*","*\\winsxs\\*","*\\wbem\\*")) | lookup hijacklibs library AS loaded_file OUTPUT islibrary | search islibrary = True | stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded dest loaded_file loaded_file_path original_file_name process_exec process_guid process_hash process_id process_name process_path service_dll_signature_exists service_dll_signature_verified signature signature_id user_id vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_dll_search_order_hijacking_hunt_with_sysmon_filter`' +search: '`sysmon` EventCode=7 NOT (process_path IN ("*\\system32\\*", "*\\syswow64\\*","*\\winsxs\\*","*\\wbem\\*")) | lookup local=t hijacklibs library AS loaded_file OUTPUT islibrary | search islibrary = True | stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded dest loaded_file loaded_file_path original_file_name process_exec process_guid process_hash process_id process_name process_path service_dll_signature_exists service_dll_signature_verified signature signature_id user_id vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_dll_search_order_hijacking_hunt_with_sysmon_filter`' how_to_implement: The search is written against the latest Sysmon TA 4.0 https://splunkbase.splunk.com/app/5709. For this specific event ID 7, the sysmon TA will extract the ImageLoaded name to the loaded_file field which is used in the search to compare against the hijacklibs lookup. known_false_positives: False positives will be present based on paths. Filter or add other paths to the exclusion as needed. Some applications may legitimately load libraries from non-standard paths. references: diff --git a/detections/endpoint/windows_domain_admin_impersonation_indicator.yml b/detections/endpoint/windows_domain_admin_impersonation_indicator.yml index bdd740f73b4..5c0981bdc1f 100644 --- a/detections/endpoint/windows_domain_admin_impersonation_indicator.yml +++ b/detections/endpoint/windows_domain_admin_impersonation_indicator.yml @@ -1,8 +1,8 @@ name: Windows Domain Admin Impersonation Indicator id: 10381f93-6d38-470a-9c30-d25478e3bd3f -version: 12 +version: 13 creation_date: '2023-10-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Mauricio Velazco, Splunk status: production type: TTP @@ -16,7 +16,7 @@ search: |- BY _time TargetUserName GroupMembership action app dest signature_id user vendor_product - | lookup domain_admins username as TargetUserName OUTPUT username + | lookup local=t domain_admins username as TargetUserName OUTPUT username | fillnull value=NotDA username | search username = "NotDA" | `windows_domain_admin_impersonation_indicator_filter` diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index bf5c2622dda..eee16bce84a 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -1,8 +1,8 @@ name: Windows DotNet Binary in Non Standard Path id: fddf3b56-7933-11ec-98a6-acde48001122 -version: 14 +version: 15 creation_date: '2022-01-20' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: TTP @@ -45,8 +45,8 @@ search: | | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup update=true is_net_windows_file filename as process_name OUTPUT netFile - | lookup update=true is_net_windows_file originalFileName as original_file_name OUTPUT netFile + | lookup local=t update=true is_net_windows_file filename as process_name OUTPUT netFile + | lookup local=t update=true is_net_windows_file originalFileName as original_file_name OUTPUT netFile | search netFile=true | `windows_dotnet_binary_in_non_standard_path_filter` how_to_implement: | diff --git a/detections/endpoint/windows_hosts_file_access.yml b/detections/endpoint/windows_hosts_file_access.yml index 04ee00db3d4..accdd50bec1 100644 --- a/detections/endpoint/windows_hosts_file_access.yml +++ b/detections/endpoint/windows_hosts_file_access.yml @@ -1,8 +1,8 @@ name: Windows Hosts File Access id: b34bcf35-5380-4b00-b208-5531303fb751 -version: 4 +version: 5 creation_date: '2026-03-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -29,7 +29,7 @@ search: | by _time object_file_path object_file_name dest process_name process_path process_id EventCode | eval process_path = lower(process_path) - | lookup browser_process_and_path browser_process_path as process_path OUTPUT is_valid_browser_path + | lookup local=t browser_process_and_path browser_process_path as process_path OUTPUT is_valid_browser_path | eval is_valid_browser_path=coalesce(is_valid_browser_path,"false") | where is_valid_browser_path = "false" | `security_content_ctime(firstTime)` diff --git a/detections/endpoint/windows_identify_protocol_handlers.yml b/detections/endpoint/windows_identify_protocol_handlers.yml index a839ad24519..e6477a71bc9 100644 --- a/detections/endpoint/windows_identify_protocol_handlers.yml +++ b/detections/endpoint/windows_identify_protocol_handlers.yml @@ -1,8 +1,8 @@ name: Windows Identify Protocol Handlers id: bd5c311e-a6ea-48ae-a289-19a3398e3648 -version: 10 +version: 11 creation_date: '2022-07-12' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting @@ -23,7 +23,7 @@ search: |- | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` - | lookup windows_protocol_handlers handler AS process OUTPUT handler ishandler + | lookup local=t windows_protocol_handlers handler AS process OUTPUT handler ishandler | where ishandler="TRUE" | `windows_identify_protocol_handlers_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/windows_important_audit_policy_disabled.yml b/detections/endpoint/windows_important_audit_policy_disabled.yml index b9eb4aba48b..ad0f602c9e0 100644 --- a/detections/endpoint/windows_important_audit_policy_disabled.yml +++ b/detections/endpoint/windows_important_audit_policy_disabled.yml @@ -1,8 +1,8 @@ name: Windows Important Audit Policy Disabled id: 1bf500e5-1226-41d9-af5d-ed1f577929f2 -version: 8 +version: 9 creation_date: '2025-02-19' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -16,7 +16,7 @@ search: |- | rename ClientProcessId as process_id | stats min(_time) as _time values(host) as dest BY AuditPolicyChanges SubcategoryGuid, process_id - | lookup advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory + | lookup local=t advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory | `windows_important_audit_policy_disabled_filter` how_to_implement: To implement the following query, enable the audit policy sub category "Audit Audit Policy Change", and, ensure you are ingesting EventCode `4719` from your endpoints via the appropriate Splunk Add-on for Microsoft Windows. Update the macro definition with the an accurate list of Audit sub categories that you consider important for your environment. known_false_positives: No false positives have been identified at this time. diff --git a/detections/endpoint/windows_kerberos_local_successful_logon.yml b/detections/endpoint/windows_kerberos_local_successful_logon.yml index f056478f50a..af3fb835060 100644 --- a/detections/endpoint/windows_kerberos_local_successful_logon.yml +++ b/detections/endpoint/windows_kerberos_local_successful_logon.yml @@ -1,8 +1,8 @@ name: Windows Kerberos Local Successful Logon id: 8309c3a8-4d34-48ae-ad66-631658214653 -version: 15 +version: 16 creation_date: '2022-04-28' -modification_date: '2026-07-27' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: TTP @@ -31,7 +31,7 @@ search: |- src_port status subject user user_group vendor_product - | lookup update=true domain_controllers sAMAccountName as dest OUTPUT isDC + | lookup local=t update=true domain_controllers sAMAccountName as dest OUTPUT isDC | where isnull(isDC) | fields - isDC diff --git a/detections/endpoint/windows_known_abused_dll_created.yml b/detections/endpoint/windows_known_abused_dll_created.yml index 56dbfd3b2e1..e480094ba54 100644 --- a/detections/endpoint/windows_known_abused_dll_created.yml +++ b/detections/endpoint/windows_known_abused_dll_created.yml @@ -1,15 +1,15 @@ name: Windows Known Abused DLL Created id: ea91651a-772a-4b02-ac3d-985b364a5f07 -version: 11 +version: 12 creation_date: '2024-03-20' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly description: The following analytic identifies the creation of Dynamic Link Libraries (DLLs) with a known history of exploitation in atypical locations. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and filesystem events. This activity is significant as it may indicate DLL search order hijacking or sideloading, techniques used by attackers to execute arbitrary code, maintain persistence, or escalate privileges. If confirmed malicious, this activity could allow attackers to blend in with legitimate operations, posing a severe threat to system integrity and security. data_source: - Sysmon EventID 11 -search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\users\\*","*\\Windows\Temp\\*","*\\programdata\\*") Filesystem.file_name="*.dll" by Filesystem.action Filesystem.dest Filesystem.file_access_time Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time Filesystem.file_name Filesystem.file_path Filesystem.file_acl Filesystem.file_size Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product | `drop_dm_object_name(Filesystem)` | lookup hijacklibs_loaded library AS file_name OUTPUT islibrary, ttp, comment as desc | lookup hijacklibs_loaded library AS file_name excludes as file_path OUTPUT islibrary as excluded | search islibrary = TRUE AND excluded != TRUE | where isnotnull(file_name) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_known_abused_dll_created_filter`' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\users\\*","*\\Windows\Temp\\*","*\\programdata\\*") Filesystem.file_name="*.dll" by Filesystem.action Filesystem.dest Filesystem.file_access_time Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time Filesystem.file_name Filesystem.file_path Filesystem.file_acl Filesystem.file_size Filesystem.process_guid Filesystem.process_id Filesystem.user Filesystem.vendor_product | `drop_dm_object_name(Filesystem)` | lookup local=t hijacklibs_loaded library AS file_name OUTPUT islibrary, ttp, comment as desc | lookup local=t hijacklibs_loaded library AS file_name excludes as file_path OUTPUT islibrary as excluded | search islibrary = TRUE AND excluded != TRUE | where isnotnull(file_name) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_known_abused_dll_created_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` and `Filesystem` nodes of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. known_false_positives: This analytic may flag instances where DLLs are loaded by user mode programs for entirely legitimate and benign purposes. It is important for users to be aware that false positives are not only possible but likely, and that careful tuning of this analytic is necessary to distinguish between malicious activity and normal, everyday operations of applications. This may involve adjusting thresholds, whitelisting known good software, or incorporating additional context from other security tools and logs to reduce the rate of false positives. references: diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml index de0367bd262..93cd636e66b 100644 --- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml @@ -1,8 +1,8 @@ name: Windows LOLBAS Executed As Renamed File id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 10 +version: 11 creation_date: '2024-05-03' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP @@ -11,7 +11,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` latest(Processes.parent_process) as parent_process, latest(Processes.process) as process, latest(Processes.process_guid) as process_guid count, min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where NOT Processes.original_file_name IN("-","unknown") AND NOT Processes.process_path IN ("*\\Program Files*","*\\PROGRA~*","*\\Windows\\System32\\*","*\\Windows\\Syswow64\\*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product |`drop_dm_object_name(Processes)` | where NOT match(process_name, "(?i)".original_file_name) | lookup lolbas_file_path lolbas_file_name as original_file_name OUTPUT description as desc | search desc!="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lolbas_executed_as_renamed_file_filter`' +search: '| tstats `security_content_summariesonly` latest(Processes.parent_process) as parent_process, latest(Processes.process) as process, latest(Processes.process_guid) as process_guid count, min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where NOT Processes.original_file_name IN("-","unknown") AND NOT Processes.process_path IN ("*\\Program Files*","*\\PROGRA~*","*\\Windows\\System32\\*","*\\Windows\\Syswow64\\*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product |`drop_dm_object_name(Processes)` | where NOT match(process_name, "(?i)".original_file_name) | lookup local=t lolbas_file_path lolbas_file_name as original_file_name OUTPUT description as desc | search desc!="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lolbas_executed_as_renamed_file_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. known_false_positives: A certain amount of false positives are likely with this detection. MSI based installers often trigger for SETUPAPL.dll and vendors will often copy system exectables to a different path for application usage. references: diff --git a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml index 6f917fe2492..24259e1e79e 100644 --- a/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml +++ b/detections/endpoint/windows_lolbas_executed_outside_expected_path.yml @@ -1,8 +1,8 @@ name: Windows LOLBAS Executed Outside Expected Path id: 326fdf44-b90c-4d2e-adca-1fd140b10536 -version: 10 +version: 11 creation_date: '2024-05-03' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -36,8 +36,8 @@ search: | Processes.process_path Processes.user Processes.user_id Processes.vendor_product |`drop_dm_object_name(Processes)` - | lookup lolbas_file_path lolbas_file_name as process_name OUTPUT description as desc - | lookup lolbas_file_path lolbas_file_name as process_name lolbas_file_path as process_path OUTPUT description as is_lolbas_path + | lookup local=t lolbas_file_path lolbas_file_name as process_name OUTPUT description as desc + | lookup local=t lolbas_file_path lolbas_file_name as process_name lolbas_file_path as process_path OUTPUT description as is_lolbas_path | search desc!="false" AND is_lolbas_path="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_nirsoft_utilities.yml b/detections/endpoint/windows_nirsoft_utilities.yml index 5900bb891c8..41f70c18715 100644 --- a/detections/endpoint/windows_nirsoft_utilities.yml +++ b/detections/endpoint/windows_nirsoft_utilities.yml @@ -1,8 +1,8 @@ name: Windows NirSoft Utilities id: 5b2f4596-7d4c-11ec-88a7-acde48001122 -version: 10 +version: 11 creation_date: '2022-01-24' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting @@ -29,7 +29,7 @@ search: | | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup update=true is_nirsoft_software filename as process_name OUTPUT nirsoftFile + | lookup local=t update=true is_nirsoft_software filename as process_name OUTPUT nirsoftFile | search nirsoftFile=true | `windows_nirsoft_utilities_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/windows_powershell_process_with_malicious_string.yml b/detections/endpoint/windows_powershell_process_with_malicious_string.yml index b9e7b2e5fa3..3093678429b 100644 --- a/detections/endpoint/windows_powershell_process_with_malicious_string.yml +++ b/detections/endpoint/windows_powershell_process_with_malicious_string.yml @@ -1,8 +1,8 @@ name: Windows PowerShell Process With Malicious String id: 5df35d50-e1a3-4a52-a337-92e69d9b1b8a -version: 9 +version: 10 creation_date: '2025-01-13' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP @@ -24,7 +24,7 @@ search: |- | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup malicious_powershell_strings command as process + | lookup local=t malicious_powershell_strings command as process | where isnotnull(match) | `windows_powershell_process_with_malicious_string_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. diff --git a/detections/endpoint/windows_powershell_script_block_with_malicious_string.yml b/detections/endpoint/windows_powershell_script_block_with_malicious_string.yml index bda2aaccd74..8556e4f6761 100644 --- a/detections/endpoint/windows_powershell_script_block_with_malicious_string.yml +++ b/detections/endpoint/windows_powershell_script_block_with_malicious_string.yml @@ -1,15 +1,15 @@ name: Windows PowerShell Script Block With Malicious String id: 0f09cedd-10f1-4b9f-bdea-7a8b06ea575d -version: 7 +version: 8 creation_date: '2025-01-13' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP description: The following analytic detects the execution of multiple offensive toolkits and commands by leveraging PowerShell Script Block Logging (EventCode=4104). This method captures and logs the full command sent to PowerShell, allowing for the identification of suspicious activities including several well-known tools used for credential theft, lateral movement, and persistence. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and potential compromise of sensitive information within the environment. data_source: - Powershell Script Block Logging 4104 -search: '`powershell` ScriptBlockText=* EventCode=4104 | stats count min(_time) as firstTime max(_time) as lastTime list(ScriptBlockText) as command values(Guid) as Guid values(Opcode) as Opcode values(Name) as Name values(Path) as Path values(ProcessID) as ProcessID values(ScriptBlockId) as ScriptBlockId values(ScriptBlockText) as ScriptBlockText by dest signature signature_id user_id vendor_product | eval command = mvjoin(command,"\n") | lookup malicious_powershell_strings command | where isnotnull(match) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_powershell_script_block_with_malicious_string_filter`' +search: '`powershell` ScriptBlockText=* EventCode=4104 | stats count min(_time) as firstTime max(_time) as lastTime list(ScriptBlockText) as command values(Guid) as Guid values(Opcode) as Opcode values(Name) as Name values(Path) as Path values(ProcessID) as ProcessID values(ScriptBlockId) as ScriptBlockId values(ScriptBlockText) as ScriptBlockText by dest signature signature_id user_id vendor_product | eval command = mvjoin(command,"\n") | lookup local=t malicious_powershell_strings command | where isnotnull(match) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_powershell_script_block_with_malicious_string_filter`' how_to_implement: The following analytic requires PowerShell operational logs to be imported. Modify the powershell macro as needed to match the sourcetype or add index. This analytic is specific to 4104, or PowerShell Script Block Logging. known_false_positives: No false positives have been identified at this time. commands with overlap. references: diff --git a/detections/endpoint/windows_pua_named_pipe.yml b/detections/endpoint/windows_pua_named_pipe.yml index bbcf80eff0a..68a592e092c 100644 --- a/detections/endpoint/windows_pua_named_pipe.yml +++ b/detections/endpoint/windows_pua_named_pipe.yml @@ -1,8 +1,8 @@ name: Windows PUA Named Pipe id: 95b11d20-e2c6-46a5-b526-8629f5f0860a -version: 5 +version: 6 creation_date: '2025-12-08' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: Anomaly @@ -38,7 +38,7 @@ search: | count by dest dvc process_exec process_guid process_id process_path signature signature_id vendor_product pipe_name user_id Image process_name - | lookup pua_named_pipes pua_pipe_name AS pipe_name OUTPUT tool, description + | lookup local=t pua_named_pipes pua_pipe_name AS pipe_name OUTPUT tool, description | where isnotnull(tool) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_rmm_named_pipe.yml b/detections/endpoint/windows_rmm_named_pipe.yml index 9e40b67134e..fdb9a4bf18e 100644 --- a/detections/endpoint/windows_rmm_named_pipe.yml +++ b/detections/endpoint/windows_rmm_named_pipe.yml @@ -1,8 +1,8 @@ name: Windows RMM Named Pipe id: c07c7138-edf5-4a16-8b24-3842599235bf -version: 5 +version: 6 creation_date: '2025-12-08' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: Anomaly @@ -37,7 +37,7 @@ search: | count by dest dvc process_exec process_guid process_id process_path signature signature_id vendor_product pipe_name user_id Image process_name - | lookup suspicious_rmm_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, description + | lookup local=t suspicious_rmm_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, description | where isnotnull(tool) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_scheduled_task_with_suspicious_command.yml b/detections/endpoint/windows_scheduled_task_with_suspicious_command.yml index 8b118547037..876973cadb7 100644 --- a/detections/endpoint/windows_scheduled_task_with_suspicious_command.yml +++ b/detections/endpoint/windows_scheduled_task_with_suspicious_command.yml @@ -1,8 +1,8 @@ name: Windows Scheduled Task with Suspicious Command id: 1f44c126-c26a-4dd3-83bb-0f9a0f03ecc3 -version: 9 +version: 10 creation_date: '2025-02-07' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP @@ -11,7 +11,7 @@ data_source: - Windows Event Log Security 4698 - Windows Event Log Security 4700 - Windows Event Log Security 4702 -search: "`wineventlog_security` EventCode IN (4698,4700,4702)\n| eval TaskContent = case(isnotnull(TaskContentNew),TaskContentNew,true(),TaskContent)\n| xmlkv TaskContent\n| stats count min(_time) as firstTime max(_time) as lastTime latest(Arguments) as Arguments latest(Author) as Author by Computer, Caller_User_Name, TaskName, Command, Enabled, Hidden, EventCode\n| lookup windows_suspicious_tasks task_command as Command \n| where tool == \"shell command use\" OR tool == \"suspicious paths\"\n| eval command=TaskName, process=Command+if(isnotnull(Arguments),\" \".Arguments,\"\"), src_user=Author, user = Caller_User_Name, dest = Computer, signature_id = EventCode \n| `security_content_ctime(firstTime)` \n| `security_content_ctime(lastTime)`\n| `windows_scheduled_task_with_suspicious_command_filter` " +search: "`wineventlog_security` EventCode IN (4698,4700,4702)\n| eval TaskContent = case(isnotnull(TaskContentNew),TaskContentNew,true(),TaskContent)\n| xmlkv TaskContent\n| stats count min(_time) as firstTime max(_time) as lastTime latest(Arguments) as Arguments latest(Author) as Author by Computer, Caller_User_Name, TaskName, Command, Enabled, Hidden, EventCode\n| lookup local=t windows_suspicious_tasks task_command as Command \n| where tool == \"shell command use\" OR tool == \"suspicious paths\"\n| eval command=TaskName, process=Command+if(isnotnull(Arguments),\" \".Arguments,\"\"), src_user=Author, user = Caller_User_Name, dest = Computer, signature_id = EventCode \n| `security_content_ctime(firstTime)` \n| `security_content_ctime(lastTime)`\n| `windows_scheduled_task_with_suspicious_command_filter` " how_to_implement: To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. known_false_positives: False positives are possible if legitimate applications are allowed to register tasks that call a shell to be spawned. Filter as needed based on command-line or processes that are used legitimately. Windows Defender, Google Chrome, and MS Edge updates may trigger this detection. references: diff --git a/detections/endpoint/windows_scheduled_task_with_suspicious_name.yml b/detections/endpoint/windows_scheduled_task_with_suspicious_name.yml index 872660b4e0d..e4e43f175d1 100644 --- a/detections/endpoint/windows_scheduled_task_with_suspicious_name.yml +++ b/detections/endpoint/windows_scheduled_task_with_suspicious_name.yml @@ -1,8 +1,8 @@ name: Windows Scheduled Task with Suspicious Name id: 9e9ab4e3-c9d0-4967-a197-6d755e8a7e6e -version: 9 +version: 10 creation_date: '2025-02-07' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP @@ -16,7 +16,7 @@ search: |- | eval TaskContent = case(isnotnull(TaskContentNew),TaskContentNew,true(),TaskContent) | xmlkv TaskContent | stats count min(_time) as firstTime max(_time) as lastTime latest(Arguments) as Arguments latest(Author) as Author by Computer, TaskName, Command, Enabled, Hidden,Caller_User_Name, EventCode - | lookup windows_suspicious_tasks task_name as TaskName + | lookup local=t windows_suspicious_tasks task_name as TaskName | where isnotnull(tool_type) | eval command=TaskName, process=Command+if(isnotnull(Arguments)," ".Arguments,""), src_user=Author, user = Caller_User_Name, dest = Computer | `security_content_ctime(firstTime)` diff --git a/detections/endpoint/windows_service_created_with_suspicious_service_name.yml b/detections/endpoint/windows_service_created_with_suspicious_service_name.yml index feff939ffab..99789981a91 100644 --- a/detections/endpoint/windows_service_created_with_suspicious_service_name.yml +++ b/detections/endpoint/windows_service_created_with_suspicious_service_name.yml @@ -1,8 +1,8 @@ name: Windows Service Created with Suspicious Service Name id: 35eb6d19-a497-400c-93c5-645562804b11 -version: 9 +version: 10 creation_date: '2025-02-07' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -14,7 +14,7 @@ search: |- | stats values(ImagePath) as process, count, min(_time) as firstTime, max(_time) as lastTime values(EventCode) as signature by Computer, ServiceName, StartType, ServiceType, UserID | eval process_name = replace(mvindex(split(process,"\\"),-1), "\"", "") | rename Computer as dest, ServiceName as object_name, ServiceType as object_type, UserID as user_id - | lookup windows_suspicious_services service_name as object_name + | lookup local=t windows_suspicious_services service_name as object_name | where isnotnull(tool_name) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_suspicious_c2_named_pipe.yml b/detections/endpoint/windows_suspicious_c2_named_pipe.yml index 270a890fcb7..1654dfc0f83 100644 --- a/detections/endpoint/windows_suspicious_c2_named_pipe.yml +++ b/detections/endpoint/windows_suspicious_c2_named_pipe.yml @@ -1,8 +1,8 @@ name: Windows Suspicious C2 Named Pipe id: 90599d85-dc2a-4d4c-8c59-9485c3665828 -version: 6 +version: 7 creation_date: '2025-12-08' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: TTP @@ -37,7 +37,7 @@ search: | count by dest dvc process_exec process_guid process_id process_path signature signature_id vendor_product pipe_name user_id Image process_name - | lookup suspicious_c2_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, description + | lookup local=t suspicious_c2_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, description | where isnotnull(tool) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_suspicious_named_pipe.yml b/detections/endpoint/windows_suspicious_named_pipe.yml index c77859e3b85..38cc4205615 100644 --- a/detections/endpoint/windows_suspicious_named_pipe.yml +++ b/detections/endpoint/windows_suspicious_named_pipe.yml @@ -1,8 +1,8 @@ name: Windows Suspicious Named Pipe id: 3a76d52f-a007-4a65-a37d-f313c2c83f31 -version: 5 +version: 6 creation_date: '2025-12-08' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: TTP @@ -38,7 +38,7 @@ search: | count by dest dvc process_exec process_guid process_id process_path pipe_name user_id process_name signature signature_id vendor_product - | lookup suspicious_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, type, description + | lookup local=t suspicious_named_pipes suspicious_pipe_name AS pipe_name OUTPUT tool, type, description | where isnotnull(tool) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/endpoint/windows_vulnerable_driver_installed.yml b/detections/endpoint/windows_vulnerable_driver_installed.yml index 4884e5dd26e..6f5d12c6d4d 100644 --- a/detections/endpoint/windows_vulnerable_driver_installed.yml +++ b/detections/endpoint/windows_vulnerable_driver_installed.yml @@ -1,8 +1,8 @@ name: Windows Vulnerable Driver Installed id: 1dda7586-57be-4a1b-8de1-a9ad802b9a7f -version: 11 +version: 12 creation_date: '2020-01-19' -modification_date: '2026-09-08' +modification_date: '2026-09-22' author: Dean Luxton status: production type: TTP @@ -12,7 +12,7 @@ data_source: search: |- `wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" | table _time dest EventCode ImagePath ServiceName ServiceType - | lookup loldrivers driver_name AS ImagePath OUTPUT is_driver driver_description + | lookup local=t loldrivers driver_name AS ImagePath OUTPUT is_driver driver_description | search is_driver = TRUE | `windows_vulnerable_driver_installed_filter` how_to_implement: Ensure the Splunk is collecting XmlWinEventLog:System events and the EventCode 7045 is being ingested. diff --git a/detections/endpoint/windows_vulnerable_driver_loaded.yml b/detections/endpoint/windows_vulnerable_driver_loaded.yml index 8f9d32b5501..26fcf996f6b 100644 --- a/detections/endpoint/windows_vulnerable_driver_loaded.yml +++ b/detections/endpoint/windows_vulnerable_driver_loaded.yml @@ -1,8 +1,8 @@ name: Windows Vulnerable Driver Loaded id: a2b1f1ef-221f-4187-b2a4-d4b08ec745f4 -version: 10 +version: 11 creation_date: '2022-12-31' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Hunting @@ -15,7 +15,7 @@ search: |- BY ImageLoaded dest dvc process_hash process_path signature signature_id user_id vendor_product - | lookup loldrivers driver_name AS ImageLoaded OUTPUT is_driver driver_description + | lookup local=t loldrivers driver_name AS ImageLoaded OUTPUT is_driver driver_description | search is_driver = TRUE | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/network/3cx_supply_chain_attack_network_indicators.yml b/detections/network/3cx_supply_chain_attack_network_indicators.yml index 6c02019581c..946c2451347 100644 --- a/detections/network/3cx_supply_chain_attack_network_indicators.yml +++ b/detections/network/3cx_supply_chain_attack_network_indicators.yml @@ -1,8 +1,8 @@ name: 3CX Supply Chain Attack Network Indicators id: 791b727c-deec-4fbe-a732-756131b3c5a1 -version: 11 +version: 12 creation_date: '2023-04-11' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: TTP @@ -22,7 +22,7 @@ search: | | `drop_dm_object_name(DNS)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup 3cx_ioc_domains domain as query OUTPUT Description isIOC + | lookup local=t 3cx_ioc_domains domain as query OUTPUT Description isIOC | search isIOC=true | `3cx_supply_chain_attack_network_indicators_filter` how_to_implement: To successfully implement this search you need to be ingesting information into the `Network Resolution` datamodel in the `DNS` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA''s are installed. diff --git a/detections/network/cisco_secure_firewall___binary_file_type_download.yml b/detections/network/cisco_secure_firewall___binary_file_type_download.yml index 52fa1549919..1eb6a299ddb 100644 --- a/detections/network/cisco_secure_firewall___binary_file_type_download.yml +++ b/detections/network/cisco_secure_firewall___binary_file_type_download.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Binary File Type Download id: 24b2c2e3-2ff7-4a23-b814-87f8a62028cd -version: 8 +version: 9 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -16,7 +16,7 @@ data_source: search: | `cisco_secure_firewall` EventType=FileEvent FileDirection="Download" FileType IN ("ISHIELD_MSI", "BINHEX", "BINARY_DATA", "ELF", "MACHO", "JARPACK", "TORRENT", "AUTORUN", "EICAR", "LNK", "SCR", "UNIX_SCRIPT") - | lookup cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description + | lookup local=t cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description | stats count min(_time) as firstTime max(_time) as lastTime values(uri) as uri values(ClientApplication) as ClientApplication diff --git a/detections/network/cisco_secure_firewall___blacklisted_ssl_certificate_fingerprint.yml b/detections/network/cisco_secure_firewall___blacklisted_ssl_certificate_fingerprint.yml index 7103a3112fe..68cbf8d2749 100644 --- a/detections/network/cisco_secure_firewall___blacklisted_ssl_certificate_fingerprint.yml +++ b/detections/network/cisco_secure_firewall___blacklisted_ssl_certificate_fingerprint.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint id: c43f7b49-2dab-4e76-892e-7f971c2f20f1 -version: 7 +version: 8 creation_date: '2025-04-03' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -12,7 +12,7 @@ data_source: - Cisco Secure Firewall Threat Defense Connection Event search: | `cisco_secure_firewall` EventType=* SSL_CertFingerprint=* - | lookup sslbl_ssl_certificate_blacklist SHA1 as SSL_CertFingerprint OUTPUT Listingdate, Listingreason + | lookup local=t sslbl_ssl_certificate_blacklist SHA1 as SSL_CertFingerprint OUTPUT Listingdate, Listingreason | where isnotnull(Listingreason) | stats min(_time) as firstTime max(_time) as lastTime values(dest) as dest diff --git a/detections/network/cisco_secure_firewall___file_download_over_uncommon_port.yml b/detections/network/cisco_secure_firewall___file_download_over_uncommon_port.yml index 301f42145e7..a6b4cb4e230 100644 --- a/detections/network/cisco_secure_firewall___file_download_over_uncommon_port.yml +++ b/detections/network/cisco_secure_firewall___file_download_over_uncommon_port.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - File Download Over Uncommon Port id: f26445a8-a6a2-4855-bec0-0c39e52e5b8f -version: 8 +version: 9 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: - Cisco Secure Firewall Threat Defense File Event search: | `cisco_secure_firewall` EventType=FileEvent FileDirection="Download" NOT dest_port IN (80, 443) - | lookup cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description + | lookup local=t cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description | stats count min(_time) as firstTime max(_time) as lastTime values(file_name) as file_name values(uri) as uri diff --git a/detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml b/detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml index 871d3190a60..518f8f97ff4 100644 --- a/detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml +++ b/detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Intrusion Events by Threat Activity id: b71e57e8-c571-4ff1-ae13-bc4384a9e891 -version: 10 +version: 11 creation_date: '2025-05-12' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Bhavin Patel, Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -40,11 +40,11 @@ data_source: search: | `cisco_secure_firewall` EventType=IntrusionEvent | stats count AS total_alerts, dc(signature_id) AS sig_count, values(SnortRuleGroups) AS snort_rule_groups, values(connection_id) AS connection_id, values(rule) AS rule, values(dest_port) AS dest_port, values(transport) AS transport, values(app) AS app, values(signature) AS signature, values(src) AS src BY _time dest signature_id - | lookup cisco_snort_ids_to_threat_mapping signature_id OUTPUT threat, category, message + | lookup local=t cisco_snort_ids_to_threat_mapping signature_id OUTPUT threat, category, message | where isnotnull(threat) | bin _time span=1d | stats count AS Total_Alerts, dc(signature_id) AS sig_count, values(signature_id) AS signature_id, values(category) AS category, values(message) AS message, values(snort_rule_groups) AS snort_rule_groups, values(connection_id) AS connection_id, values(rule) AS rule, values(dest_port) AS dest_port, values(transport) AS transport, values(app) AS app, values(signature) AS signature, values(src) AS src BY _time dest threat - | lookup threat_snort_count threat OUTPUT description, distinct_count_snort_ids + | lookup local=t threat_snort_count threat OUTPUT description, distinct_count_snort_ids | table _time, dest, src, threat, category, message, description, signature_id, signature, snort_rule_groups, sig_count, distinct_count_snort_ids, connection_id, rule, dest_port, transport, app | where sig_count >= distinct_count_snort_ids | `cisco_secure_firewall___intrusion_events_by_threat_activity_filter` diff --git a/detections/network/cisco_secure_firewall___malware_file_downloaded.yml b/detections/network/cisco_secure_firewall___malware_file_downloaded.yml index c4280c02106..b32cf7b6ae5 100644 --- a/detections/network/cisco_secure_firewall___malware_file_downloaded.yml +++ b/detections/network/cisco_secure_firewall___malware_file_downloaded.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Malware File Downloaded id: 3cc93f52-5aa6-4b7f-83b9-3430b1436813 -version: 8 +version: 9 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: - Cisco Secure Firewall Threat Defense File Event search: | `cisco_secure_firewall` EventType=FileEvent SHA_Disposition="Malware" FileDirection="Download" - | lookup cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description + | lookup local=t cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description | stats count min(_time) as firstTime max(_time) as lastTime values(uri) as uri values(ClientApplication) as ClientApplication diff --git a/detections/network/cisco_secure_firewall___remote_access_software_usage_traffic.yml b/detections/network/cisco_secure_firewall___remote_access_software_usage_traffic.yml index 64793a40b67..8b32c0275e8 100644 --- a/detections/network/cisco_secure_firewall___remote_access_software_usage_traffic.yml +++ b/detections/network/cisco_secure_firewall___remote_access_software_usage_traffic.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Remote Access Software Usage Traffic id: ac54d39e-a75d-4f42-971d-006db3a0423a -version: 9 +version: 10 creation_date: '2025-05-28' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -26,7 +26,7 @@ search: | count by src ClientApplication action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup cisco_secure_firewall_appid_remote_mgmt_and_desktop_tools appName AS ClientApplication OUTPUT category, appDescription as Description + | lookup local=t cisco_secure_firewall_appid_remote_mgmt_and_desktop_tools appName AS ClientApplication OUTPUT category, appDescription as Description | search category IN ("remote administration", "remote desktop control") | `remote_access_software_usage_exceptions` | `cisco_secure_firewall___remote_access_software_usage_traffic_filter` diff --git a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml index 12bf62ba6f7..972b7aeb41c 100644 --- a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml +++ b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall - Repeated Malware Downloads id: aeff2bb5-3483-48d4-9be8-c8976194be1e -version: 10 +version: 11 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -12,7 +12,7 @@ data_source: - Cisco Secure Firewall Threat Defense File Event search: | `cisco_secure_firewall` EventType=FileEvent SHA_Disposition="Malware" FileDirection="Download" - | lookup cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description + | lookup local=t cisco_secure_firewall_filetype_lookup Name as FileType OUTPUT Description | bin _time span=5m | stats count min(_time) as firstTime max(_time) as lastTime values(uri) as uri diff --git a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml index 6d14e36bc2c..c3a4f069d99 100644 --- a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml +++ b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml @@ -1,8 +1,8 @@ name: Detect hosts connecting to dynamic domain providers id: a1e761ac-1344-4dbd-88b2-3f34c912d359 -version: 13 +version: 14 creation_date: '2019-10-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Bhavin Patel, Splunk status: production type: TTP @@ -18,8 +18,8 @@ search: | DNS.reply_code_id DNS.src DNS.vendor_product | `drop_dm_object_name("DNS")` | `security_content_ctime(firstTime)` - | lookup update=true dynamic_dns_providers_default dynamic_dns_domains as query OUTPUTNEW isDynDNS_default - | lookup update=true dynamic_dns_providers_local dynamic_dns_domains as query OUTPUTNEW isDynDNS_local + | lookup local=t update=true dynamic_dns_providers_default dynamic_dns_domains as query OUTPUTNEW isDynDNS_default + | lookup local=t update=true dynamic_dns_providers_local dynamic_dns_domains as query OUTPUTNEW isDynDNS_local | eval isDynDNS = coalesce(isDynDNS_local,isDynDNS_default) |fields - isDynDNS_default, isDynDNS_local| search isDynDNS=True | `detect_hosts_connecting_to_dynamic_domain_providers_filter` diff --git a/detections/network/detect_remote_access_software_usage_dns.yml b/detections/network/detect_remote_access_software_usage_dns.yml index 1171d0c58f2..dc927f67a6f 100644 --- a/detections/network/detect_remote_access_software_usage_dns.yml +++ b/detections/network/detect_remote_access_software_usage_dns.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage DNS id: a16b797d-e309-41bd-8ba0-5067dae2e4be -version: 14 +version: 15 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -22,7 +22,7 @@ search: | | `drop_dm_object_name("DNS")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup remote_access_software remote_domain AS query OUTPUT isutility, description as signature, + | lookup local=t remote_access_software remote_domain AS query OUTPUT isutility, description as signature, comment_reference as desc, category | eval dest = query | search isutility = True diff --git a/detections/network/detect_remote_access_software_usage_traffic.yml b/detections/network/detect_remote_access_software_usage_traffic.yml index 17fe2236b8d..f0883920752 100644 --- a/detections/network/detect_remote_access_software_usage_traffic.yml +++ b/detections/network/detect_remote_access_software_usage_traffic.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage Traffic id: 885ea672-07ee-475a-879e-60d28aa5dd42 -version: 16 +version: 17 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -30,7 +30,7 @@ search: | | `drop_dm_object_name("All_Traffic")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | lookup remote_access_software remote_appid AS app OUTPUT isutility, description as signature, comment_reference as desc, category + | lookup local=t remote_access_software remote_appid AS app OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = True | `remote_access_software_usage_exceptions` | `detect_remote_access_software_usage_traffic_filter` diff --git a/detections/network/http_c2_framework_user_agent.yml b/detections/network/http_c2_framework_user_agent.yml index a442d265c5b..db8c77cf01a 100644 --- a/detections/network/http_c2_framework_user_agent.yml +++ b/detections/network/http_c2_framework_user_agent.yml @@ -1,8 +1,8 @@ name: HTTP C2 Framework User Agent id: 229dc225-6abe-4d28-89fd-edf874086162 -version: 5 +version: 6 creation_date: '2026-01-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Ravent Tait, Splunk status: production type: TTP @@ -15,7 +15,7 @@ search: |- BY Web.http_user_agent Web.http_method, Web.url, Web.url_length Web.src, Web.dest | `drop_dm_object_name("Web")` - | lookup suspicious_c2_user_agents c2_user_agent AS http_user_agent OUTPUT tool, description + | lookup local=t suspicious_c2_user_agents c2_user_agent AS http_user_agent OUTPUT tool, description | where isnotnull(tool) | stats count min(firstTime) as first_seen max(lastTime) as last_seen BY tool url http_user_agent diff --git a/detections/network/http_malware_user_agent.yml b/detections/network/http_malware_user_agent.yml index df79a6ba052..5490fc528f5 100644 --- a/detections/network/http_malware_user_agent.yml +++ b/detections/network/http_malware_user_agent.yml @@ -1,8 +1,8 @@ name: HTTP Malware User Agent id: 8c4866e4-f488-4253-8537-7dc4f954c292 -version: 5 +version: 6 creation_date: '2026-01-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: TTP @@ -15,7 +15,7 @@ search: |- BY Web.http_user_agent Web.http_method, Web.url, Web.url_length Web.src, Web.dest | `drop_dm_object_name("Web")` - | lookup malware_user_agents malware_user_agent AS http_user_agent OUTPUT malware + | lookup local=t malware_user_agents malware_user_agent AS http_user_agent OUTPUT malware | where isnotnull(malware) | stats count min(firstTime) as first_seen max(lastTime) as last_seen BY malware url http_user_agent diff --git a/detections/network/http_pua_user_agent.yml b/detections/network/http_pua_user_agent.yml index a20df5452a6..b05dd3386e3 100644 --- a/detections/network/http_pua_user_agent.yml +++ b/detections/network/http_pua_user_agent.yml @@ -1,8 +1,8 @@ name: HTTP PUA User Agent id: 21af5447-734f-4549-956b-7a255cb2b032 -version: 5 +version: 6 creation_date: '2026-01-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: Anomaly @@ -15,7 +15,7 @@ search: |- BY Web.http_user_agent Web.http_method, Web.url, Web.url_length Web.src, Web.dest | `drop_dm_object_name("Web")` - | lookup pua_user_agents pua_user_agent AS http_user_agent OUTPUT tool + | lookup local=t pua_user_agents pua_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | stats count min(firstTime) as first_seen max(lastTime) as last_seen BY tool url http_user_agent diff --git a/detections/network/http_rmm_user_agent.yml b/detections/network/http_rmm_user_agent.yml index dde34ab9e5d..1ad50d30cb3 100644 --- a/detections/network/http_rmm_user_agent.yml +++ b/detections/network/http_rmm_user_agent.yml @@ -1,8 +1,8 @@ name: HTTP RMM User Agent id: 61884b02-0dcf-44c5-9094-db33bac09fa6 -version: 5 +version: 6 creation_date: '2026-01-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: Anomaly @@ -15,7 +15,7 @@ search: |- BY Web.http_user_agent Web.http_method, Web.url, Web.url_length Web.src, Web.dest | `drop_dm_object_name("Web")` - | lookup rmm_user_agents rmm_user_agent AS http_user_agent OUTPUT tool + | lookup local=t rmm_user_agents rmm_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | stats count min(firstTime) as first_seen max(lastTime) as last_seen BY tool url http_user_agent diff --git a/detections/network/prohibited_network_traffic_allowed.yml b/detections/network/prohibited_network_traffic_allowed.yml index 2235c3e236d..d305d4f139f 100644 --- a/detections/network/prohibited_network_traffic_allowed.yml +++ b/detections/network/prohibited_network_traffic_allowed.yml @@ -1,8 +1,8 @@ name: Prohibited Network Traffic Allowed id: ce5a0962-849f-4720-a678-753fe6674479 -version: 15 +version: 16 creation_date: '2020-04-29' -modification_date: '2026-09-08' +modification_date: '2026-09-22' author: Rico Valdez, Splunk status: production type: Anomaly @@ -36,7 +36,7 @@ search: |- All_Traffic.dest_port All_Traffic.dvc All_Traffic.transport All_Traffic.vendor_product - | lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note + | lookup local=t update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` diff --git a/detections/web/detect_remote_access_software_usage_url.yml b/detections/web/detect_remote_access_software_usage_url.yml index 1a8700de2a4..228dd2e6a28 100644 --- a/detections/web/detect_remote_access_software_usage_url.yml +++ b/detections/web/detect_remote_access_software_usage_url.yml @@ -1,8 +1,8 @@ name: Detect Remote Access Software Usage URL id: 9296f515-073c-43a5-88ec-eda5a4626654 -version: 16 +version: 17 creation_date: '2024-03-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: Anomaly @@ -35,7 +35,7 @@ search: | | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("Web")` - | lookup remote_access_software remote_domain AS url_domain OUTPUT isutility, description as signature, comment_reference + | lookup local=t remote_access_software remote_domain AS url_domain OUTPUT isutility, description as signature, comment_reference as desc, category | search isutility = True | `remote_access_software_usage_exceptions` diff --git a/detections/web/http_scripting_tool_user_agent.yml b/detections/web/http_scripting_tool_user_agent.yml index 629822d8ddf..2a3328ef834 100644 --- a/detections/web/http_scripting_tool_user_agent.yml +++ b/detections/web/http_scripting_tool_user_agent.yml @@ -1,8 +1,8 @@ name: HTTP Scripting Tool User Agent id: 04430b4e-5ca8-4e88-98b5-d6bcf54f8393 -version: 6 +version: 7 creation_date: '2025-10-21' -modification_date: '2026-06-15' +modification_date: '2026-09-22' author: Raven Tait, Splunk status: production type: Anomaly @@ -22,7 +22,7 @@ search: |- | `security_content_ctime(lastTime)` | `drop_dm_object_name(Web)` | eval http_user_agent = lower(http_user_agent) - | lookup scripting_tools_user_agents tool_user_agent AS http_user_agent OUTPUT tool + | lookup local=t scripting_tools_user_agents tool_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | stats count min(firstTime) as first_seen diff --git a/macros/base64decode.yml b/macros/base64decode.yml index 99fe5b4f96b..75877181140 100644 --- a/macros/base64decode.yml +++ b/macros/base64decode.yml @@ -1,10 +1,10 @@ name: base64decode id: fc2a1c3c-3251-418d-b411-7e62303e2cb3 -version: 1 +version: 2 creation_date: '2024-01-10' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Splunk Threat Research Team description: Content based conversion of UTF8/UTF16 based base64 encoding. Not a full implementation, but good enough for context without additional app installation. -definition: 'eval b64x_split=split($b64in$,"") | lookup char_conversion_matrix base64char as b64x_split OUTPUT base64bin as b64x_bin | eval b64x_join=mvjoin(b64x_bin,"") | rex field=b64x_join "(?.{8})" max_match=0 | lookup char_conversion_matrix bin as b64x_by8 output ascii as b64x_out | eval $b64in$_decode=mvjoin(b64x_out,"") | fields - b64x_* | eval $b64in$_decode = replace(replace($b64in$_decode,":NUL:",""),":SPACE:"," ") | rex field=$b64in$_decode mode=sed "s/\x00//g"' +definition: 'eval b64x_split=split($b64in$,"") | lookup local=t char_conversion_matrix base64char as b64x_split OUTPUT base64bin as b64x_bin | eval b64x_join=mvjoin(b64x_bin,"") | rex field=b64x_join "(?.{8})" max_match=0 | lookup local=t char_conversion_matrix bin as b64x_by8 output ascii as b64x_out | eval $b64in$_decode=mvjoin(b64x_out,"") | fields - b64x_* | eval $b64in$_decode = replace(replace($b64in$_decode,":NUL:",""),":SPACE:"," ") | rex field=$b64in$_decode mode=sed "s/\x00//g"' arguments: - b64in diff --git a/macros/remote_access_software_usage_exceptions.yml b/macros/remote_access_software_usage_exceptions.yml index 882b3c7b887..adeff11e2b3 100644 --- a/macros/remote_access_software_usage_exceptions.yml +++ b/macros/remote_access_software_usage_exceptions.yml @@ -1,8 +1,8 @@ name: remote_access_software_usage_exceptions id: 4b0c9d7e-6fe2-404d-87b0-80e11c9a11f1 -version: 1 +version: 2 creation_date: '2024-07-09' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Splunk Threat Research Team description: Macro used with remote access monitoring content to define exception lookup and usage. Returns filtered results based on contents of remote_access_software_usage_exception.csv -definition: 'eval exception_asset = CASE(isnotnull(src),src,isnotnull(dest),dest) | lookup update=true asset_lookup_by_str asset as exception_asset OUTPUTNEW asset as asset_temp_field | eval asset_temp_field = CASE(isnull(asset_temp_field),exception_asset,true(),asset_temp_field ) | lookup remote_access_software_exceptions asset as asset_temp_field software as signature OUTPUT exception as rmm_exception, exception_date as rmm_exception_date, exception_ttl_days as rmm_exception_ttl_days, comment as rmm_exception_comment | eval rmm_exception = mvdedup(mvfilter(NOT match(rmm_exception,"false"))), rmm_exception_date = mvdedup(mvfilter(NOT match(rmm_exception_date,"false"))), rmm_exception_ttl_days = mvdedup(mvfilter(NOT match(rmm_exception_ttl_days,"false"))), rmm_exception_comment = mvdedup(mvfilter(NOT match(rmm_exception_comment,"false"))), rmm_exception_end_date = relative_time(strptime(rmm_exception_date, "%Y-%m-%d"), "+"+rmm_exception_ttl_days+"d"), rmm_exception_end = CASE((now() >= rmm_exception_end_date),"TRUE",(now() < rmm_exception_end_date),"FALSE",(match(rmm_exception,"(?i)true") AND isnull(rmm_exception_ttl_days)),"UNLIMITED") | search NOT (rmm_exception = TRUE AND rmm_exception_end IN ("FALSE","UNLIMITED")) | fields - asset_temp_field,exception_asset' +definition: 'eval exception_asset = CASE(isnotnull(src),src,isnotnull(dest),dest) | lookup local=t update=true asset_lookup_by_str asset as exception_asset OUTPUTNEW asset as asset_temp_field | eval asset_temp_field = CASE(isnull(asset_temp_field),exception_asset,true(),asset_temp_field ) | lookup local=t remote_access_software_exceptions asset as asset_temp_field software as signature OUTPUT exception as rmm_exception, exception_date as rmm_exception_date, exception_ttl_days as rmm_exception_ttl_days, comment as rmm_exception_comment | eval rmm_exception = mvdedup(mvfilter(NOT match(rmm_exception,"false"))), rmm_exception_date = mvdedup(mvfilter(NOT match(rmm_exception_date,"false"))), rmm_exception_ttl_days = mvdedup(mvfilter(NOT match(rmm_exception_ttl_days,"false"))), rmm_exception_comment = mvdedup(mvfilter(NOT match(rmm_exception_comment,"false"))), rmm_exception_end_date = relative_time(strptime(rmm_exception_date, "%Y-%m-%d"), "+"+rmm_exception_ttl_days+"d"), rmm_exception_end = CASE((now() >= rmm_exception_end_date),"TRUE",(now() < rmm_exception_end_date),"FALSE",(match(rmm_exception,"(?i)true") AND isnull(rmm_exception_ttl_days)),"UNLIMITED") | search NOT (rmm_exception = TRUE AND rmm_exception_end IN ("FALSE","UNLIMITED")) | fields - asset_temp_field,exception_asset' diff --git a/macros/suspicious_writes.yml b/macros/suspicious_writes.yml index 40c6421b8dc..a86d06c69cb 100644 --- a/macros/suspicious_writes.yml +++ b/macros/suspicious_writes.yml @@ -1,8 +1,8 @@ name: suspicious_writes id: 6983de37-2a08-4c42-80a2-fe404edd19b4 -version: 1 +version: 2 creation_date: '2019-10-16' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Splunk Threat Research Team description: This macro limites the output to file names that have been marked as suspicious -definition: lookup suspicious_writes_lookup file as file_name OUTPUT note as "Reference" | search "Reference" != False +definition: lookup local=t suspicious_writes_lookup file as file_name OUTPUT note as "Reference" | search "Reference" != False From 84965819bfe674fe87e87ef6b3324ac846558404 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 24 Sep 2026 01:43:58 +0200 Subject: [PATCH 02/10] Update common_ransomware_extensions.yml --- detections/endpoint/common_ransomware_extensions.yml | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 8f922873d49..7fb53d11a58 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,8 +1,8 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -version: 22 +version: 23 creation_date: '2019-10-16' -modification_date: '2026-07-02' +modification_date: '2026-09-22' author: David Dorsey, Michael Haag, Nasreddine Bencherchali, Splunk, Steven Dick status: production type: TTP @@ -56,7 +56,7 @@ search: | Filesystem.user Filesystem.vendor_product | `drop_dm_object_name(Filesystem)` | rex field=file_name "(?(\.[^\.]+){1,2})$" - | lookup update=true ransomware_extensions_lookup Extensions AS file_extension OUTPUT Extensions Name + | lookup local=t update=true ransomware_extensions_lookup Extensions AS file_extension OUTPUT Extensions Name | search Name !=False | stats min(firstTime) as firstTime max(lastTime) as lastTime @@ -105,6 +105,9 @@ intermediate_findings: type: system score: 50 message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $file_extension$ extension. This extension and behavior may indicate a $Name$ ransomware attack. +threat_objects: + - field: file_path + type: file_path analytic_story: - Rhysida Ransomware - Prestige Ransomware From 1f180344cf054f4d73a319a47e322ae06a7cf164 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 24 Sep 2026 02:45:31 +0200 Subject: [PATCH 03/10] more fixes --- ...ial_access_from_browser_password_store.yml | 40 ++++- .../windows_defender_asr_audit_events.yml | 50 ++++-- .../windows_defender_asr_block_events.yml | 54 +++++-- ...s_known_abused_dll_loaded_suspiciously.yml | 146 +++++++++++++++++- 4 files changed, 246 insertions(+), 44 deletions(-) diff --git a/detections/endpoint/windows_credential_access_from_browser_password_store.yml b/detections/endpoint/windows_credential_access_from_browser_password_store.yml index 53e4dea2ce8..694b94d3938 100644 --- a/detections/endpoint/windows_credential_access_from_browser_password_store.yml +++ b/detections/endpoint/windows_credential_access_from_browser_password_store.yml @@ -1,15 +1,42 @@ name: Windows Credential Access From Browser Password Store id: 72013a8e-5cea-408a-9d51-5585386b4d69 -version: 23 +version: 24 creation_date: '2024-03-20' -modification_date: '2026-06-25' +modification_date: '2026-09-22' author: Teoderick Contreras, Bhavin Patel Splunk status: production type: Anomaly -description: The following analytic identifies a possible non-common browser process accessing its browser user data profile. This tactic/technique has been observed in various Trojan Stealers, such as SnakeKeylogger, which attempt to gather sensitive browser information and credentials as part of their exfiltration strategy. Detecting this anomaly can serve as a valuable pivot for identifying processes that access lists of browser user data profiles unexpectedly. This detection uses a lookup file `browser_app_list` that maintains a list of well known browser applications and the browser paths that are allowed to access the browser user data profiles. +description: |- + The following analytic identifies a possible non-common browser process accessing its browser user data profile. + This tactic/technique has been observed in various Trojan Stealers, such as SnakeKeylogger, which attempt to gather sensitive browser information and credentials as part of their exfiltration strategy. + Detecting this anomaly can serve as a valuable pivot for identifying processes that access lists of browser user data profiles unexpectedly. + This detection uses a lookup file `browser_app_list` that maintains a list of well known browser applications and the browser paths that are allowed to access the browser user data profiles. data_source: - Windows Event Log Security 4663 -search: '`wineventlog_security` EventCode=4663 | stats count by _time object_file_path object_file_name dest process_name process_path process_id EventCode | lookup browser_app_list browser_object_path as object_file_path OUTPUT browser_process_name isAllowed | stats count min(_time) as firstTime max(_time) as lastTime values(object_file_name) values(object_file_path) values(browser_process_name) as browser_process_name by dest process_name process_path process_id EventCode isAllowed | rex field=process_name "(?[^\\\\]+)$" | eval isMalicious=if(match(browser_process_name, extracted_process_name), "0", "1") | where isMalicious=1 and isAllowed="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_credential_access_from_browser_password_store_filter`' +search: |- + `wineventlog_security` + EventCode=4663 + + | stats count by _time object_file_path object_file_name + dest process_name + process_path process_id EventCode + + | lookup local=t browser_app_list browser_object_path as object_file_path OUTPUT browser_process_name isAllowed + + | stats count min(_time) as firstTime + max(_time) as lastTime + values(object_file_name) + values(object_file_path) + values(browser_process_name) as browser_process_name + by dest process_name process_path process_id EventCode isAllowed + + | rex field=process_name "(?[^\\\\]+)$" + | eval isMalicious=if(match(browser_process_name, extracted_process_name), "0", "1") + | where isMalicious=1 and isAllowed="false" + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_credential_access_from_browser_password_store_filter` how_to_implement: To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663. For 4663, enable "Audit Object Access" in Group Policy. Then check the two boxes listed for both "Success" and "Failure." This search may trigger on a browser application that is not included in the browser_app_list lookup file. known_false_positives: The lookup file `browser_app_list` may not contain all the browser applications that are allowed to access the browser user data profiles. Consider updating the lookup files to add allowed object paths for the browser applications that are not included in the lookup file. references: @@ -29,7 +56,10 @@ intermediate_findings: - field: dest type: system score: 20 - message: A non-common browser process $process_name$ accessing browser user data folder on $dest$ + message: A non-common browser process [$process_name$] accessing browser user data folder on $dest$ +threat_objects: + - field: process_name + type: process_name analytic_story: - StealC Stealer - Salt Typhoon diff --git a/detections/endpoint/windows_defender_asr_audit_events.yml b/detections/endpoint/windows_defender_asr_audit_events.yml index f6983833e1e..0f46b9fe56b 100644 --- a/detections/endpoint/windows_defender_asr_audit_events.yml +++ b/detections/endpoint/windows_defender_asr_audit_events.yml @@ -1,33 +1,46 @@ name: Windows Defender ASR Audit Events id: 0e4d46b1-22bd-4f0e-8337-ca6f60ad4bea -version: 9 +version: 10 creation_date: '2023-12-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Anomaly -description: This detection searches for Windows Defender ASR audit events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. ASR rules are applied to processes and applications. When a process or application attempts to perform an action that is blocked by an ASR rule, an event is generated. This detection searches for ASR audit events that are generated when a process or application attempts to perform an action that would be blocked by an ASR rule, but is allowed to proceed for auditing purposes. +description: |- + This detection searches for ASR audit events that are generated when a process or application attempts to perform an action that would be blocked by an ASR rule, but is allowed to proceed for auditing purposes. data_source: - Windows Event Log Defender 1122 - Windows Event Log Defender 1125 - - Windows Event Log Defender 1126 - Windows Event Log Defender 1132 - Windows Event Log Defender 1134 search: |- - `ms_defender` EventCode IN (1122, 1125, 1126, 1132, 1134) - | stats count min(_time) as firstTime max(_time) as lastTime - BY host, Process_Name, Target_Commandline, - Path, ID, EventCode - | lookup asr_rules ID OUTPUT ASR_Rule - | fillnull value=NULL - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | rename host as dest - | `windows_defender_asr_audit_events_filter` + `ms_defender` + EventCode IN ( + 1122, + 1125, + 1132, + 1134 + ) + | fillnull + | stats count min(_time) as firstTime + max(_time) as lastTime + by host EventCode + Parent_CommandLine Process_Name Target_Commandline + Path ID RuleType + + | lookup local=t asr_rules ID OUTPUT ASR_Rule + + | rename host as dest + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_defender_asr_audit_events_filter` how_to_implement: The following analytic requires collection of Windows Defender Operational logs in either XML or multi-line. To collect, setup a new input for the Windows Defender Operational logs. In addition, it does require a lookup that maps the ID to ASR Rule name. Note that Audit and block Event IDs have different fields, therefore the analytic will need to be modified for each type of event. -known_false_positives: False positives are expected from legitimate applications generating events that are similar to those generated by malicious activity. For example, Event ID 1122 is generated when a process attempts to load a DLL that is blocked by an ASR rule. This can be triggered by legitimate applications that attempt to load DLLs that are not blocked by ASR rules. This is audit only. +known_false_positives: |- + Some false positives are expected initially as the ASR rules are tuned and configured. references: - https://asrgen.streamlit.app/ + - https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-overview drilldown_searches: - name: View the detection results for - "$dest$" search: '%original_detection_search% | search dest = "$dest$"' @@ -42,7 +55,12 @@ intermediate_findings: - field: dest type: system score: 20 - message: ASR audit event, $ASR_Rule$, was triggered on $dest$. + message: The ASR audit event [$ASR_Rule$] was triggered on [$dest$]. +threat_objects: + - field: Parent_CommandLine + type: parent_process + - field: Process_Name + type: file_path analytic_story: - Windows Attack Surface Reduction asset_type: Endpoint diff --git a/detections/endpoint/windows_defender_asr_block_events.yml b/detections/endpoint/windows_defender_asr_block_events.yml index 8a05832e331..27f81ccd1e4 100644 --- a/detections/endpoint/windows_defender_asr_block_events.yml +++ b/detections/endpoint/windows_defender_asr_block_events.yml @@ -1,12 +1,14 @@ name: Windows Defender ASR Block Events id: 026f5f4e-e99f-4155-9e63-911ba587300b -version: 10 +version: 11 creation_date: '2023-12-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Michael Haag, Splunk status: production type: Anomaly -description: This detection searches for Windows Defender ASR block events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. ASR rules are applied to processes and applications. When a process or application attempts to perform an action that is blocked by an ASR rule, an event is generated. This detection searches for ASR block events that are generated when a process or application attempts to perform an action that is blocked by an ASR rule. Typically, these will be enabled in block most after auditing and tuning the ASR rules themselves. Set to TTP once tuned. +description: |- + This detection searches for ASR block events that are generated when a process or application attempts to perform an action that is blocked by an ASR rule. + Typically, these will be enabled in block most after auditing and tuning the ASR rules themselves. data_source: - Windows Event Log Defender 1121 - Windows Event Log Defender 1126 @@ -14,20 +16,35 @@ data_source: - Windows Event Log Defender 1131 - Windows Event Log Defender 1133 search: |- - `ms_defender` EventCode IN (1121, 1126, 1129, 1131, 1133) - | stats count min(_time) as firstTime max(_time) as lastTime - BY host, Path, Parent_Commandline, - Process_Name, ID, EventCode - | lookup asr_rules ID OUTPUT ASR_Rule - | fillnull value=NULL - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | rename host as dest - | `windows_defender_asr_block_events_filter` -how_to_implement: The following analytic requires collection of Windows Defender Operational logs in either XML or multi-line. To collect, setup a new input for the Windows Defender Operational logs. In addition, it does require a lookup that maps the ID to ASR Rule name. Note that Audit and block Event IDs have different fields, therefore the analytic will need to be modified for each type of event. -known_false_positives: False positives are expected from legitimate applications generating events that are similar to those generated by malicious activity. For example, Event ID 1122 is generated when a process attempts to load a DLL that is blocked by an ASR rule. This can be triggered by legitimate applications that attempt to load DLLs that are not blocked by ASR rules. This is block only. + `ms_defender` + EventCode IN ( + 1121, + 1126, + 1129, + 1131, + 1133 + ) + | fillnull + | stats count min(_time) as firstTime + max(_time) as lastTime + by host EventCode + Parent_CommandLine Process_Name Target_Commandline + Path ID RuleType + + | lookup local=t asr_rules ID OUTPUT ASR_Rule + + | rename host as dest + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_defender_asr_block_events_filter` +how_to_implement: |- + The following analytic requires collection of Windows Defender Operational logs in either XML or multi-line. To collect, setup a new input for the Windows Defender Operational logs. In addition, it does require a lookup that maps the ID to ASR Rule name. Note that Audit and block Event IDs have different fields, therefore the analytic will need to be modified for each type of event. +known_false_positives: |- + Some false positives are expected initially as the ASR rules are tuned and configured. references: - https://asrgen.streamlit.app/ + - https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-overview drilldown_searches: - name: View the detection results for - "$dest$" search: '%original_detection_search% | search dest = "$dest$"' @@ -42,7 +59,12 @@ intermediate_findings: - field: dest type: system score: 20 - message: ASR block event, $ASR_Rule$, was triggered on $dest$. + message: The ASR block event [$ASR_Rule$] was triggered on [$dest$]. +threat_objects: + - field: Parent_CommandLine + type: parent_process + - field: Process_Name + type: file_path analytic_story: - Windows Attack Surface Reduction asset_type: Endpoint diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 22ae61333d5..61cbe9dc5df 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -1,17 +1,144 @@ name: Windows Known Abused DLL Loaded Suspiciously id: dd6d1f16-adc0-4e87-9c34-06189516b803 -version: 12 +version: 13 creation_date: '2024-04-06' -modification_date: '2026-05-13' +modification_date: '2026-09-22' author: Steven Dick status: production type: TTP -description: The following analytic detects when DLLs with known abuse history are loaded from an unusual location. This activity may represent an attacker performing a DLL search order or sideload hijacking technique. These techniques are used to gain persistence as well as elevate privileges on the target system. This detection relies on Sysmon EID7 and is compatible with all Officla Sysmon TA versions. +description: |- + The following analytic detects when DLLs with known abuse history are loaded from an unusual location. + This activity may represent an attacker performing a DLL search order or sideload hijacking technique. + These techniques are used to gain persistence as well as elevate privileges on the target system. data_source: - Sysmon EventID 7 -search: '`sysmon` ImageLoaded EventCode=7 NOT ImageLoaded IN ("*\\Program Files*","*\\system32\\*", "*\\syswow64\\*","*\\winsxs\\*","*\\wbem\\*") | stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded dest process_exec process_guid process_hash process_id process_path service_dll_signature_exists service_dll_signature_verified signature signature_id user_id vendor_product loaded_file | rename Image as process | eval process_name = case(isnotnull(process),replace(process,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), loaded_file_path = case(isnotnull(loaded_file), replace(loaded_file, "(:[\w\. ]+)", "")), loaded_file = case(isnotnull(loaded_file),replace(loaded_file,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), user = case(NOT user IN ("-"), replace(user, "(.*)\\\(.+)$","\2")) | lookup hijacklibs_loaded library AS loaded_file OUTPUT islibrary comment as desc | lookup hijacklibs_loaded library AS loaded_file excludes as loaded_file_path OUTPUT islibrary as excluded | search islibrary = TRUE AND excluded = false | stats count min(_time) as firstTime max(_time) as lastTime by dest loaded_file loaded_file_path process process_exec process_guid process_hash process_id process_name process_path service_dll_signature_exists service_dll_signature_verified signature signature_id user_id vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_known_abused_dll_loaded_suspiciously_filter`' -how_to_implement: The following analytic requires Sysmon operational logs to be imported, with EID7 being mapped to the process_name field. Modify the sysmon macro as needed to match the sourcetype or add index. -known_false_positives: DLLs being loaded by user mode programs for legitimate reasons. +search: |- + `sysmon` + ImageLoaded + EventCode=7 + + NOT ImageLoaded IN ( + "C:\\$WINDOWS.~BT\\*", + "C:\\$WinREAgent\\*", + "C:\\Windows\\SoftwareDistribution\\*", + "C:\\Windows\\SyChpe32\\*", + "C:\\Windows\\System32\\*", + "C:\\Windows\\SystemTemp\\*", + "C:\\Windows\\SysWOW64\\*", + "C:\\Windows\\WinSxS\\*" + ) + + NOT ( + ImageLoaded="C:\\Windows\\Temp\\*" + Image IN ( + "C:\\Windows\\WinSxS\\arm64*", + "C:\\Windows\\UUS\\arm64\\*" + ) + Image IN ( + "*\\TiWorker.exe", + "*\\wuaucltcore.exe" + ) + ) + + NOT ( + ImageLoaded="C:\\Windows\\Microsoft.NET\\*" + ImageLoaded="*\\cscui.dll" + ) + + NOT ( + ImageLoaded="C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*" + ImageLoaded="*\\version.dll" + ) + + NOT ( + ImageLoaded="C:\\Program Files\\WindowsApps\\Microsoft.DirectXRuntime_*" + ImageLoaded="*\\d3dx9_43.dll" + ) + + NOT ImageLoaded="C:\\Windows\\ImmersiveControlPanel\\SystemSettings.dll" + + NOT ( + ImageLoaded="C:\\Program Files\\Microsoft\\Exchange Server\\*" + ImageLoaded="*\\mswb7.dll" + ) + + NOT ( + ImageLoaded="C:\\Program Files\\Arsenal-Image-Mounter-*" + ImageLoaded IN ( + "*\\mi.dll", + "*\\miutils.dl" + ) + ) + + NOT ( + Image="C:\\Program Files\\Common Files\\microsoft shared\\ClickToRun\\OfficeClickToRun.exe" + ImageLoaded="C:\\Program Files\\Common Files\\microsoft shared\\ClickToRun\\AppVPolicy.dll" + ) + + NOT ImageLoaded="C:\\Packages\\Plugins\\Microsoft.GuestConfiguration.ConfigurationforWindows\\*" + + NOT ( + Image IN ( + "C:\\Program Files\\WindowsApps\\DellInc.DellSupportAssistforPCs*", + "C:\\Windows\\System32\\backgroundTaskHost.exe" + ) + ImageLoaded="C:\\Program Files\\WindowsApps\\DellInc.DellSupportAssistforPCs*" + ) + + NOT ( + ImageLoaded="C:\\Program Files\\WindowsApps\\DellInc.DellSupportAssistforPCs\\*" + ImageLoaded="*\\wldp.dll" + ) + + NOT ( + Image IN ( + "C:\\Program Files\\CheckPoint\\*", + "C:\\Program Files (x86)\\CheckPoint\\*" + ) + Image="*\\SmartConsole.exe" + ImageLoaded IN ( + "C:\\Program Files\\CheckPoint\\*", + "C:\\Program Files (x86)\\CheckPoint\\*" + ) + ImageLoaded="*\\PolicyManager.dll" + ) + + | stats count min(_time) as firstTime + max(_time) as lastTime + + by Image ImageLoaded dest process_exec + process_guid process_hash process_id + process_path service_dll_signature_exists + service_dll_signature_verified + signature `signature_id` user_id + vendor_product loaded_file + + | rename Image as process + | eval process_name = case(isnotnull(process),replace(process,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), + loaded_file_path = case(isnotnull(loaded_file), replace(loaded_file, "(:[\w\. ]+)", "")), + loaded_file = case(isnotnull(loaded_file),replace(loaded_file,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), + user = case(NOT user IN ("-"), replace(user, "(.*)\\\(.+)$","\2")) + + | lookup local=t hijacklibs_loaded library AS loaded_file OUTPUT islibrary comment as desc + + | lookup local=t hijacklibs_loaded library AS loaded_file excludes as loaded_file_path OUTPUT islibrary as excluded | search islibrary = TRUE AND excluded = false + + | stats count min(_time) as firstTime + max(_time) as lastTime + + by dest loaded_file loaded_file_path process + process_exec process_guid process_hash process_id + process_name process_path service_dll_signature_exists + service_dll_signature_verified signature + signature_id user_id vendor_product + + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_known_abused_dll_loaded_suspiciously_filter` +how_to_implement: |- + The following analytic requires Sysmon operational logs to be ingested, with EventID 7 being mapped to the process_name field. Modify the sysmon macro as needed to match the sourcetype or add index. +known_false_positives: |- + False positives are expected from third party applications and other legitimate system processes located in Program Files and other similar locations. Filter as needed. references: - https://attack.mitre.org/techniques/T1574/002/ - https://hijacklibs.net/api/ @@ -27,11 +154,16 @@ drilldown_searches: earliest_offset: 7d latest_offset: "0" finding: - title: The module [$loaded_file$] was loaded from an unusual location. + title: The module [$loaded_file$] was loaded from an unusual location on [$dest$]. Which may indicate a DLL search order or sideload hijacking technique. entity: field: dest type: system score: 50 +threat_objects: + - field: Image + type: file_path + - field: ImageLoaded + type: loaded_file analytic_story: - SolarWinds WHD RCE Post Exploitation - Windows Defense Evasion Tactics From 1c38f66cdc042da097ad3512e30cd9b1c8eed812 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 24 Sep 2026 02:48:32 +0200 Subject: [PATCH 04/10] Update windows_known_abused_dll_loaded_suspiciously.yml --- .../endpoint/windows_known_abused_dll_loaded_suspiciously.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 61cbe9dc5df..1dd9a734d26 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -110,7 +110,7 @@ search: |- process_guid process_hash process_id process_path service_dll_signature_exists service_dll_signature_verified - signature `signature_id` user_id + signature signature_id user_id vendor_product loaded_file | rename Image as process From e3e54d0566367755b595a518d9701c553903c2b2 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 24 Sep 2026 11:31:39 +0200 Subject: [PATCH 05/10] fix field name typo --- detections/endpoint/windows_defender_asr_audit_events.yml | 6 ++++-- detections/endpoint/windows_defender_asr_block_events.yml | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/windows_defender_asr_audit_events.yml b/detections/endpoint/windows_defender_asr_audit_events.yml index 0f46b9fe56b..879e96cd554 100644 --- a/detections/endpoint/windows_defender_asr_audit_events.yml +++ b/detections/endpoint/windows_defender_asr_audit_events.yml @@ -25,7 +25,7 @@ search: |- | stats count min(_time) as firstTime max(_time) as lastTime by host EventCode - Parent_CommandLine Process_Name Target_Commandline + Parent_Commandline Process_Name Target_Commandline Path ID RuleType | lookup local=t asr_rules ID OUTPUT ASR_Rule @@ -57,8 +57,10 @@ intermediate_findings: score: 20 message: The ASR audit event [$ASR_Rule$] was triggered on [$dest$]. threat_objects: - - field: Parent_CommandLine + - field: Parent_Commandline type: parent_process + - field: Target_Commandline + type: process - field: Process_Name type: file_path analytic_story: diff --git a/detections/endpoint/windows_defender_asr_block_events.yml b/detections/endpoint/windows_defender_asr_block_events.yml index 27f81ccd1e4..ef0f87e9a69 100644 --- a/detections/endpoint/windows_defender_asr_block_events.yml +++ b/detections/endpoint/windows_defender_asr_block_events.yml @@ -28,7 +28,7 @@ search: |- | stats count min(_time) as firstTime max(_time) as lastTime by host EventCode - Parent_CommandLine Process_Name Target_Commandline + Parent_Commandline Process_Name Target_Commandline Path ID RuleType | lookup local=t asr_rules ID OUTPUT ASR_Rule @@ -61,8 +61,10 @@ intermediate_findings: score: 20 message: The ASR block event [$ASR_Rule$] was triggered on [$dest$]. threat_objects: - - field: Parent_CommandLine + - field: Parent_Commandline type: parent_process + - field: Target_Commandline + type: process - field: Process_Name type: file_path analytic_story: From 048fec0fafbcb1c2b753cd06b4d635573162c346 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Tue, 29 Sep 2026 15:26:38 +0200 Subject: [PATCH 06/10] update logic and lookup --- ...s_known_abused_dll_loaded_suspiciously.yml | 40 +- lookups/csv/hijacklibs_loaded.csv | 1772 ++++++++--------- lookups/csv/hijacklibs_loaded.yml | 4 +- 3 files changed, 900 insertions(+), 916 deletions(-) diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 1dd9a734d26..8e96e2cfc42 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -66,7 +66,7 @@ search: |- ImageLoaded="C:\\Program Files\\Arsenal-Image-Mounter-*" ImageLoaded IN ( "*\\mi.dll", - "*\\miutils.dl" + "*\\miutils.dll" ) ) @@ -103,34 +103,18 @@ search: |- ImageLoaded="*\\PolicyManager.dll" ) - | stats count min(_time) as firstTime - max(_time) as lastTime - - by Image ImageLoaded dest process_exec - process_guid process_hash process_id - process_path service_dll_signature_exists - service_dll_signature_verified - signature signature_id user_id - vendor_product loaded_file - - | rename Image as process - | eval process_name = case(isnotnull(process),replace(process,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), - loaded_file_path = case(isnotnull(loaded_file), replace(loaded_file, "(:[\w\. ]+)", "")), - loaded_file = case(isnotnull(loaded_file),replace(loaded_file,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")), - user = case(NOT user IN ("-"), replace(user, "(.*)\\\(.+)$","\2")) - - | lookup local=t hijacklibs_loaded library AS loaded_file OUTPUT islibrary comment as desc - - | lookup local=t hijacklibs_loaded library AS loaded_file excludes as loaded_file_path OUTPUT islibrary as excluded | search islibrary = TRUE AND excluded = false + | lookup local=t hijacklibs_loaded library AS loaded_file OUTPUT islibrary comment as reference + | lookup local=t hijacklibs_loaded library AS loaded_file excludes AS loaded_file_path OUTPUT islibrary AS excluded + | where islibrary="TRUE" AND isnull(excluded) | stats count min(_time) as firstTime max(_time) as lastTime - by dest loaded_file loaded_file_path process - process_exec process_guid process_hash process_id - process_name process_path service_dll_signature_exists + by dest loaded_file loaded_file_path process_exec + process_guid process_hash process_id process_name + process_path service_dll_signature_exists service_dll_signature_verified signature - signature_id user_id vendor_product + signature_id user user_id reference vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` @@ -154,16 +138,16 @@ drilldown_searches: earliest_offset: 7d latest_offset: "0" finding: - title: The module [$loaded_file$] was loaded from an unusual location on [$dest$]. Which may indicate a DLL search order or sideload hijacking technique. + title: The module [$loaded_file$] was loaded from an unusual location [$loaded_file_path$] on [$dest$]. Which may indicate a DLL search order or sideload hijacking technique. entity: field: dest type: system score: 50 threat_objects: - - field: Image + - field: process_path + type: file_path + - field: loaded_file_path type: file_path - - field: ImageLoaded - type: loaded_file analytic_story: - SolarWinds WHD RCE Post Exploitation - Windows Defense Evasion Tactics diff --git a/lookups/csv/hijacklibs_loaded.csv b/lookups/csv/hijacklibs_loaded.csv index d3523b22ad7..cb93a27993b 100644 --- a/lookups/csv/hijacklibs_loaded.csv +++ b/lookups/csv/hijacklibs_loaded.csv @@ -1,887 +1,887 @@ islibrary,library,excludes,ttp,comment -TRUE,aclui.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,aclui.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,acrodistdll.dll,*\Program Files\Adobe\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf -TRUE,acrodistdll.dll,*\Acrobat\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf -TRUE,activeds.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,activeds.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,adsldpc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,adsldpc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,aepic.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,aepic.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,apphelp.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,apphelp.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,applicationframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,applicationframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,appvpolicy.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,appwiz.cpl,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ -TRUE,appwiz.cpl,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ -TRUE,appxalluserstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxalluserstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxdeploymentclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxdeploymentclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,archiveint.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,archiveint.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ashldres.dll,*\Program Files\McAfee.com\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf -TRUE,atl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,atl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,atltracetoolui.dll,*\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,audioses.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,audioses.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,auditpolcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,auditpolcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authfwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authfwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,avrt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,avrt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,basicnetutils.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,basicnetutils.dll,*\Program Files\BAIDU\BAIDUPINYIN\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,batmeter.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,batmeter.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,bcd.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcd.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47langs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47langs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47mrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47mrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcrypt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,bcrypt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,bderepair.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bootmenuux.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bootux.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cabinet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cabinet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cabview.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cabview.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,certcli.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,certcli.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,certenroll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,certenroll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cfgmgr32.dll,*\Windows\System32\*,T1574.002, -TRUE,cfgmgr32.dll,*\Windows\SysWOW64\*,T1574.002, -TRUE,chrome_frame_helper.dll,*\Appdata\local\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,chrome_frame_helper.dll,*\Program Files\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,ciscosparklauncher.dll,*\Appdata\local\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,ciscosparklauncher.dll,*\AppData\Local\Programs\Cisco Spark\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,classicexplorer32.dll,*\Program Files\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets -TRUE,classicexplorer32.dll,*\Program Files\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets -TRUE,cldapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cldapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clipc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clipc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clusapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clusapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmpbk32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmpbk32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cmutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coloradapterclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coloradapterclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,colorui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,colorui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,comdlg32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,comdlg32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,commfunc.dll,*\Program Files\Lenovo\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,configmanager2.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,connect.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,connect.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,coredplus.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coremessaging.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coremessaging.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coreuicomponents.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coreuicomponents.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,credui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,credui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptdll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptdll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptsp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cryptsp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cryptui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptxml.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptxml.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscobj.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscobj.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,d2d1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d2d1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10warp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10warp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d11.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d11.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d12.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d12.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d9.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d9.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\windows kits\10\redist\d3d\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\microsoft\edge\application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Program Files\Google\Chrome\Application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Appdata\local\microsoft\teams\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\Microsoft\Teams\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dx9_43.dll,*\Windows\System32\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,d3dx9_43.dll,*\Windows\SysWOW64\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,dataexchange.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dataexchange.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,davclnt.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,davclnt.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgmodel.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dbgmodel.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dbgmodel.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dcntel.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,defragproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,defragproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,desktopshellext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,desktopshellext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,deviceassociation.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,deviceassociation.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicecredential.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicecredential.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicepairing.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,devicepairing.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,devobj.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devobj.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devrtl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devrtl.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc6.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc6.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,directmanipulation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,directmanipulation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dismapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dismapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dismcore.dll,*\Windows\System32\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ -TRUE,dismcore.dll,*\Windows\SysWOW64\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ -TRUE,dmcfgutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcfgutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcmnutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcmnutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcommandlineutils.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dmcommandlineutils.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dmenrollengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmenrollengine.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmenterprisediagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmiso8601utils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmiso8601utils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmoleaututils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmoleaututils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmprocessxmlfiltered.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmprocessxmlfiltered.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmpushproxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmpushproxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmxmlhelputils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmxmlhelputils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dnsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dnsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3api.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3api.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3cfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3cfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dpx.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dpx.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,drprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,drprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,drvstore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,drvstore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsparse.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsparse.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsprop.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsprop.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsreg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsreg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsrole.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsrole.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dui70.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dui70.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,duser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,duser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dusmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dusmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwrite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwrite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxcore.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dxcore.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dxgi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxgi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxva2.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxva2.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dynamoapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappprxy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappprxy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,edgeiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,edgeiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,edputil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,edputil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsadu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsadu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,esent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,esent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,execmodelproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,execmodelproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,explorerframe.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,explorerframe.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,facesdk.dll,*\Program Files\luxand\facesdk\bin\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,fastprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fastprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,faultrep.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,faultrep.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fddevquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fddevquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,feclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,feclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fhcfg.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fhcfg.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fhsvcctl.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,firewallapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,firewallapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,flightsettings.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,flightsettings.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fltlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fltlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,formdll.dll,*\Program Files\Common Files\Microsoft Shared\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1 -TRUE,framedynos.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,framedynos.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fveapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fveapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fveskybackup.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fvewiz.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fwbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwbase.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwcfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwcfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpolicyiomgr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpolicyiomgr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpuclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpuclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsst.dll,*\Windows\System32\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/ -TRUE,fxstiff.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxstiff.dll,*\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,getuname.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,getuname.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,gflagsui.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,glib-2.0.dll,*\Program Files\VMware\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,gpapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,gpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,hha.dll,*\Windows\System32\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hha.dll,*\Windows\SysWOW64\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hha.dll,*\Program Files\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hid.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hid.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hnetmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hnetmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hpcustpartui.dll,*\Program Files\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html -TRUE,hpqhvsei.dll,*\Program Files\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,httpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,httpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,icmp.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,icmp.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,idstore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,idstore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ieadvpack.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ieadvpack.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iedkcs32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iedkcs32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iernonce.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ -TRUE,iernonce.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ -TRUE,iertutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iertutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifmon.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifmon.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,ifsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,inproclogger.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iphlpapi.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iphlpapi.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iri.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iri.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsidsc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsidsc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsiexe.dll,*\Windows\System32\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC -TRUE,iscsiexe.dll,*\Windows\SysWOW64\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC -TRUE,iscsium.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsium.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,iumbase.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iumsdk.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,joinutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,joinutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,kdstub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ksuser.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ksuser.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ktmw32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ktmw32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ldvpocx.ocx,*\Program Files\Symantec_Client_Security\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox -TRUE,ldvpocx.ocx,*\Program Files\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox -TRUE,libcares-2.dll,*\git\mingw64\*,T1574.002,https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/ -TRUE,libvlc.dll,*\Program Files\VideoLAN\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,licensemanagerapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,licensemanagerapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,licensingdiagspp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,licensingdiagspp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,linkinfo.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,linkinfo.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,lmiguardiandll.dll,*\Program Files\LogMeIn\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,loadperf.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,loadperf.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,lockdown.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600 -TRUE,lockhostingframework.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,log.dll,*\Program Files\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,logoncli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,logoncli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,logoncontroller.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,logoncontroller.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lpksetupproxyserv.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lpksetupproxyserv.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lrwizdll.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,magnification.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,magnification.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,maintenanceui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mapistub.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mapistub.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mbaexmlparser.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mdmdiagnostics.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfc42u.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mfc42u.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mfcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfplat.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfplat.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,midimap.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,midimap.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mintdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,miutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,miutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mlang.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mlang.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mmdevapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mmdevapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mobilenetworking.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mobilenetworking.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mozglue.dll,*\Program Files\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*\Program Files\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*\Program Files\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*\AppData\Local\Mozilla Firefox\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mpclient.dll,*\Program Files\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ -TRUE,mpclient.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ -TRUE,mpr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mpr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mprapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mprapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mpsvc.dll,*\Program Files\Windows Defender\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ -TRUE,mpsvc.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ -TRUE,mrmcorer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mrmcorer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msacm32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msacm32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscms.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscms.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscoree.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscoree.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,mscorsvc.dll,*\Windows\Microsoft.NET\Framework64\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,msctf.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msctf.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msctfmonitor.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msctfmonitor.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdrm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdrm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdtctm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msftedit.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,msftedit.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,msi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msiso.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msiso.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msutb.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msutb.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msvcp110_win.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msvcp110_win.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msvcr100.dll,*\Windows\System32\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,msvcr100.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mswb7.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswb7.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswsock.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswsock.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msxml3.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msxml3.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mtxclu.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mtxclu.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,napinsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,napinsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ncrypt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ncrypt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ndfapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ndfapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netapi32.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netid.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netid.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netiohlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netiohlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netjoin.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netjoin.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netplwiz.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netplwiz.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netprofm.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netprofm.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netprovfw.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netprovfw.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netsetupapi.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netsetupapi.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netshell.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netshell.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nettrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,networkexplorer.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,networkexplorer.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,newdev.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,newdev.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ninput.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ninput.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlaapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlaapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlansp_c.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nlansp_c.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,npmproxy.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,npmproxy.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nshhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshwfp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshwfp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntdsapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntdsapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntlanman.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntlanman.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntlmshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntlmshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntmarta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntmarta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntshrui.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntshrui.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nvsmartmax.dll,*\Program Files\NVIDIA Corporation\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos -TRUE,oleacc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,oleacc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,omadmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,omadmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,onex.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,onex.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,opcservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,opcservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,opera_elf.dll,*\Appdata\local\programs\opera\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412 -TRUE,osbaseln.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osbaseln.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osksupport.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osuninst.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osuninst.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,outllib.dll,*\Program Files\Microsoft Office\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 -TRUE,outllib.dll,*\Program Files\Microsoft Office\Root\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 -TRUE,p2p.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2p.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2pnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2pnetsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p9np.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,p9np.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pcaui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pcaui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,peerdistsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,peerdistsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pkeyhelper.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,pla.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pla.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,playsndsrv.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,playsndsrv.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,pnrpnsp.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pnrpnsp.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,policymanager.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,policymanager.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,polstore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,polstore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,powrprof.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,powrprof.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,printui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,printui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,prntvpt.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,prntvpt.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,profapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,profapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,propsys.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,propsys.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,proximitycommon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,proximitycommon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,proximityservicepal.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,prvdmofcomp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,prvdmofcomp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,puiapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,puiapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,python39.dll,*\Program Files\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*\Appdata\local\Temp\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*\Users\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,qrt.dll,*\Program Files\F-Secure\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/ -TRUE,radcui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,radcui.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasdlg.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,rasdlg.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,rasgcw.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rasgcw.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rasman.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasman.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasmontr.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasmontr.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rastls.dll,*\Program Files\Symantec\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf -TRUE,rcdll.dll,*\Program Files\Windows Kits\10\bin\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,reagent.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,reagent.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,regapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,regapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,reseteng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resetengine.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rjvplatform.dll,*\Windows\System32\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 -TRUE,rjvplatform.dll,*\Windows\SysWOW64\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 -TRUE,rmclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rmclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rpcnsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rpcnsh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rtutils.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtutils.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtworkq.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtworkq.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rzlog4cpp_logger.dll,*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia -TRUE,safestore32.dll,*\Program Files\Sophos\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf -TRUE,samcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samlib.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samlib.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sapi_onecore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sapi_onecore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sas.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sas.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scansetting.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scansetting.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scecli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scecli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,schedcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,schedcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,secur32.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,secur32.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,security.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,security.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,sensapi.dll,*\Windows\System32\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 -TRUE,sensapi.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 -TRUE,shell32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,shell32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,shfolder.dll,*\Windows\System32\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 -TRUE,shfolder.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 -TRUE,siteadv.dll,*\Program Files\SiteAdvisor\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf -TRUE,slc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,slc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,smadhook32c.dll,*\Program Files\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,snmpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,snmpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spectrumsyncclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppc.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppc.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppcext.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,sppcext.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srclient.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srclient.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srmtrace.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srmtrace.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srpapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srpapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srvcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srvcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ssp.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp_isv.exe_rsaenh.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sspicli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sspicli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ssshim.dll,*\Windows\System32\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 -TRUE,ssshim.dll,*\Windows\SysWOW64\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 -TRUE,staterepository.core.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,staterepository.core.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,structuredquery.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,structuredquery.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sxshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sxshared.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,symsrv.dll,*\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,systemsettingsthresholdadminflowui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tbs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tbs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tdh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tdh.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,textshaping.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,textshaping.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,timesync.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tmdbglog.dll,*\Program Files\Trend Micro\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/ -TRUE,tosbtkbd.dll,*\Program Files\Toshiba\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,tpmcoreprovisioning.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,tpmcoreprovisioning.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,tquery.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tquery.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tsworkspace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tsworkspace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ttdrecord.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ttdrecord.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,twext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinui.appcore.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinui.appcore.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uianimation.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uianimation.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uiautomationcore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uiautomationcore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uireng.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uireng.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uiribbon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uiribbon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,umpdc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,umpdc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,unattend.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,unityplayer.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,updatepolicy.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,updatepolicy.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,upshared.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,urlmon.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,urlmon.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,userenv.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,userenv.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,utildll.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,utildll.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxinit.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxinit.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxtheme.dll,*\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxtheme.dll,*\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vaultcli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vaultcli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vdsutil.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vdsutil.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vender.dll,*\Program Files\ASUS\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,vender.dll,*\Program Files\ASUS\VGA COM\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,version.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,version.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,vftrace.dll,*\Program Files\CyberArk\Endpoint Privilege Manager\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,virtdisk.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,virtdisk.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ -TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ -TRUE,vntfxf32.dll,*\Program Files\Venta\VentaFax & Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,vsodscpl.dll,*\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/ -TRUE,vssapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vssapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vsstrace.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vsstrace.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wbemprox.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemprox.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemsvc.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemsvc.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wcmapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wcmapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wcnnetsh.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdscore.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdscore.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,webservices.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,webservices.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wecapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wecapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wer.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wer.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wevtapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wevtapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,whhelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,whhelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wimgapi.dll,*\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,wimgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,wimgapi.dll,*\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,winbio.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winbio.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winbrand.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winbrand.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windows.storage.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.search.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.search.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.ui.immersive.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,windows.ui.immersive.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,windowscodecs.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowscodecs.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowscodecsext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowscodecsext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowsperformancerecordercontrol.dll,*\Program Files\windows kits\10\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecordercontrol.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecordercontrol.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecorderui.dll,*\Program Files\Windows Kits\10\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,windowsudk.shellcommon.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowsudk.shellcommon.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winhttp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winhttp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wininet.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wininet.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winipsec.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winipsec.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmde.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmm.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmm.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winnsi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winnsi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winrnr.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winrnr.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winscard.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winscard.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winsqlite3.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsqlite3.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsta.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsta.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsync.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winsync.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winutils.dll,*\Program Files\Palo Alto Networks\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/ -TRUE,wkscli.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wkscli.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlanapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlanapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wldp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wldp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlidprov.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wlidprov.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiclnt.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmiclnt.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmidcom.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmidcom.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiutils.dll,*\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiutils.dll,*\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmpdui.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmsgapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmsgapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wofutil.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wofutil.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wpdshext.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wpdshext.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wsc.dll,*\Program Files\AVAST Software\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2 -TRUE,wscapi.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wscapi.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wsdapi.dll,*\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,wsdapi.dll,*\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,wshbth.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wshbth.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wshelper.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wshelper.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wsmsvc.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wsmsvc.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wtsapi32.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wtsapi32.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwancfg.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwancfg.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwapi.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwapi.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xmllite.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xmllite.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xolehlp.dll,*\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xolehlp.dll,*\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xpsservices.dll,*\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,xpsservices.dll,*\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,xwizards.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwizards.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwtpw32.dll,*\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwtpw32.dll,*\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,aclui.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,aclui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,acrodistdll.dll,*:\\Program Files\\Adobe\\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf +TRUE,acrodistdll.dll,*\\Acrobat\\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf +TRUE,activeds.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,activeds.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,adsldpc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,adsldpc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,aepic.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,aepic.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,apphelp.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,apphelp.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,applicationframe.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,applicationframe.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,appvpolicy.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,appwiz.cpl,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ +TRUE,appwiz.cpl,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ +TRUE,appxalluserstore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxalluserstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxdeploymentclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxdeploymentclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,archiveint.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,archiveint.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ashldres.dll,*:\\Program Files\\McAfee.com\\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf +TRUE,atl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,atl.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,atltracetoolui.dll,*:\\Program Files\\Microsoft Visual Studio 11.0\\Common7\\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,audioses.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,audioses.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,auditpolcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,auditpolcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authfwcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authfwcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authz.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authz.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,avrt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,avrt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,basicnetutils.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,basicnetutils.dll,*:\\Program Files\\BAIDU\\BAIDUPINYIN\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,batmeter.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,batmeter.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,bcd.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcd.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47langs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47langs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47mrm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47mrm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcrypt.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,bcrypt.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,bderepair.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bootmenuux.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bootux.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cabinet.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cabinet.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cabview.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cabview.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,certcli.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,certcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,certenroll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,certenroll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cfgmgr32.dll,*:\\Windows\\System32\\*,T1574.002, +TRUE,cfgmgr32.dll,*:\\Windows\\SysWOW64\\*,T1574.002, +TRUE,chrome_frame_helper.dll,*\\Appdata\\local\\Google\\Chrome\\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,chrome_frame_helper.dll,*:\\Program Files\\Google\\Chrome\\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,ciscosparklauncher.dll,*\\Appdata\\local\\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,ciscosparklauncher.dll,*\\AppData\\Local\\Programs\\Cisco Spark\\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,classicexplorer32.dll,*:\\Program Files\\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets +TRUE,classicexplorer32.dll,*:\\Program Files\\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets +TRUE,cldapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cldapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clipc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clipc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clusapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clusapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmpbk32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmpbk32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cmutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coloradapterclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coloradapterclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,colorui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,colorui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,comdlg32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,comdlg32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,commfunc.dll,*:\\Program Files\\Lenovo\\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,configmanager2.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,connect.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,connect.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,coredplus.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coremessaging.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coremessaging.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coreuicomponents.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coreuicomponents.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,credui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,credui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptbase.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptdll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptdll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptsp.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cryptsp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cryptui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptxml.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptxml.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscobj.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscobj.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscui.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscui.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,d2d1.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d2d1.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10warp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10warp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d11.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d11.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d12.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d12.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d9.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d9.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\bin\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\bin\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\redist\\d3d\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\redist\\d3d\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\cisco systems\\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\microsoft\\edge\\application\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Program Files\\Google\\Chrome\\Application\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*\\Appdata\\local\\microsoft\\teams\\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*\\Microsoft\\Teams\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dx9_43.dll,*:\\Windows\\System32\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,d3dx9_43.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,dataexchange.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dataexchange.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,davclnt.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,davclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Program Files\\microsoft office\\root\\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\cisco systems\\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\microsoft office\\root\\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Program Files\\microsoft office\\root\\vfs\\programfilesx86\\microsoft analysis services\\as oledb\\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgmodel.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dbgmodel.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dbgmodel.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dcntel.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dcomp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dcomp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,defragproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,defragproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,desktopshellext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,desktopshellext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,deviceassociation.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,deviceassociation.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicecredential.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicecredential.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicepairing.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,devicepairing.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,devobj.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devobj.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devrtl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devrtl.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcmonitor.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcmonitor.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc6.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc6.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,directmanipulation.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,directmanipulation.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dismapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dismapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dismcore.dll,*:\\Windows\\System32\\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ +TRUE,dismcore.dll,*:\\Windows\\SysWOW64\\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ +TRUE,dmcfgutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcfgutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcmnutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcmnutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcommandlineutils.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dmcommandlineutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dmenrollengine.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmenrollengine.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmenterprisediagnostics.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmiso8601utils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmiso8601utils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmoleaututils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmoleaututils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmprocessxmlfiltered.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmprocessxmlfiltered.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmpushproxy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmpushproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmxmlhelputils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmxmlhelputils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dnsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dnsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3api.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3api.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3cfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3cfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dpx.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dpx.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,drprov.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,drprov.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,drvstore.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,drvstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsparse.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsparse.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsprop.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsprop.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsreg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsreg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsrole.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsrole.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dui70.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dui70.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,duser.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,duser.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dusmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dusmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwrite.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwrite.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxcore.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dxcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dxgi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxgi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxva2.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxva2.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dynamoapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappprxy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappprxy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,edgeiso.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,edgeiso.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,edputil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,edputil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsadu.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsadu.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,esent.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,esent.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,execmodelproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,execmodelproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,explorerframe.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,explorerframe.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,facesdk.dll,*:\\Program Files\\luxand\\facesdk\\bin\\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,fastprox.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fastprox.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,faultrep.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,faultrep.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fddevquery.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fddevquery.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,feclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,feclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fhcfg.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fhcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fhsvcctl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,firewallapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,firewallapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,flightsettings.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,flightsettings.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fltlib.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fltlib.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,formdll.dll,*:\\Program Files\\Common Files\\Microsoft Shared\\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1 +TRUE,framedynos.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,framedynos.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fveapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fveapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fveskybackup.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fvewiz.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fwbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwbase.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpolicyiomgr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpolicyiomgr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpuclnt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpuclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\\Windows\\System32\\driverstore\\filerepository\\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsst.dll,*:\\Windows\\System32\\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/ +TRUE,fxstiff.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxstiff.dll,*:\\Windows\\System32\\driverstore\\filerepository\\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,getuname.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,getuname.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,gflagsui.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,gpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,gpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,hha.dll,*:\\Windows\\System32\\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hha.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hha.dll,*:\\Program Files\\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hid.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hid.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hnetmon.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hnetmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hpcustpartui.dll,*:\\Program Files\\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html +TRUE,hpqhvsei.dll,*:\\Program Files\\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,httpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,httpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,icmp.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,icmp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,idstore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,idstore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ieadvpack.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ieadvpack.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iedkcs32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iedkcs32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iernonce.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ +TRUE,iernonce.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ +TRUE,iertutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iertutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifmon.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,ifsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,inproclogger.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iphlpapi.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iphlpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iri.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iri.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsidsc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsidsc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsiexe.dll,*:\\Windows\\System32\\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC +TRUE,iscsiexe.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC +TRUE,iscsium.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsium.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,isv.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,isv.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,iumbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iumsdk.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,joinutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,joinutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,kdstub.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ksuser.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ksuser.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ktmw32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ktmw32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ldvpocx.ocx,*:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox +TRUE,ldvpocx.ocx,*:\\Program Files\\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox +TRUE,libcares-2.dll,*\\git\\mingw64\\*,T1574.002,https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/ +TRUE,libvlc.dll,*:\\Program Files\\VideoLAN\\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,licensemanagerapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,licensemanagerapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,licensingdiagspp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,licensingdiagspp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,linkinfo.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,linkinfo.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn\\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn\\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,loadperf.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,loadperf.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,lockdown.dll,*:\\Program Files\\McAfee\\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600 +TRUE,lockhostingframework.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,log.dll,*:\\Program Files\\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,logoncli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,logoncli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,logoncontroller.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,logoncontroller.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lpksetupproxyserv.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lpksetupproxyserv.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lrwizdll.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,magnification.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,magnification.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,maintenanceui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mapistub.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mapistub.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mbaexmlparser.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mdmdiagnostics.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfc42u.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mfc42u.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mfcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfplat.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfplat.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,midimap.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,midimap.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mintdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,miutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,miutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mlang.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mlang.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mmdevapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mmdevapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mobilenetworking.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mobilenetworking.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mozglue.dll,*:\\Program Files\\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*:\\Program Files\\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*:\\Program Files\\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*\\AppData\\Local\\Mozilla Firefox\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mpclient.dll,*:\\Program Files\\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ +TRUE,mpclient.dll,*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ +TRUE,mpr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mpr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mprapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mprapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mpsvc.dll,*:\\Program Files\\Windows Defender\\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ +TRUE,mpsvc.dll,*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ +TRUE,mrmcorer.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mrmcorer.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msacm32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msacm32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscms.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscms.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscoree.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscoree.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscorsvc.dll,*:\\Windows\\Microsoft.NET\\Framework\\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,mscorsvc.dll,*:\\Windows\\Microsoft.NET\\Framework64\\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,msctf.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msctf.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msctfmonitor.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msctfmonitor.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdrm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdrm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdtctm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msftedit.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,msftedit.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,msi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msiso.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msiso.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msutb.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msutb.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msvcp110_win.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msvcp110_win.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msvcr100.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,msvcr100.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mswb7.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswb7.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswsock.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswsock.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msxml3.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msxml3.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mtxclu.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mtxclu.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,napinsp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,napinsp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ncrypt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ncrypt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ndfapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ndfapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netid.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netid.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netiohlp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netiohlp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netjoin.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netjoin.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netplwiz.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netplwiz.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netprofm.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netprofm.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netprovfw.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netprovfw.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netsetupapi.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netsetupapi.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netshell.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netshell.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nettrace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,networkexplorer.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,networkexplorer.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,newdev.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,newdev.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ninput.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ninput.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlaapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlaapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlansp_c.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nlansp_c.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,npmproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,npmproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nshhttp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshhttp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshipsec.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshipsec.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshwfp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshwfp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntdsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntdsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntlanman.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntlanman.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntlmshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntlmshared.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntmarta.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntmarta.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntshrui.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntshrui.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nvsmartmax.dll,*:\\Program Files\\NVIDIA Corporation\\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos +TRUE,oleacc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,oleacc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,omadmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,omadmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,onex.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,onex.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,opcservices.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,opcservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,opera_elf.dll,*\\Appdata\\local\\programs\\opera\\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412 +TRUE,osbaseln.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osbaseln.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osksupport.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osuninst.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osuninst.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,outllib.dll,*:\\Program Files\\Microsoft Office\\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 +TRUE,outllib.dll,*:\\Program Files\\Microsoft Office\\Root\\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 +TRUE,p2p.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2p.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2pnetsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2pnetsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p9np.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,p9np.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pcaui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pcaui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pdh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,peerdistsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,peerdistsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pkeyhelper.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,pla.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pla.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,playsndsrv.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,playsndsrv.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,pnrpnsp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pnrpnsp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,policymanager.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,policymanager.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,polstore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,polstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,powrprof.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,powrprof.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,printui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,printui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,prntvpt.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,prntvpt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,profapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,profapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,propsys.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,propsys.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,proximitycommon.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,proximitycommon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,proximityservicepal.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,prvdmofcomp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,prvdmofcomp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,puiapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,puiapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,python39.dll,*:\\Program Files\\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\VC\\SecurityIssueAnalysis\\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*\\Users\\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,qrt.dll,*:\\Program Files\\F-Secure\\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/ +TRUE,radcui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,radcui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasdlg.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,rasdlg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,rasgcw.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rasgcw.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rasman.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasman.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasmontr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasmontr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rastls.dll,*:\\Program Files\\Symantec\\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf +TRUE,rcdll.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,reagent.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,reagent.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,regapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,regapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,reseteng.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resetengine.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rjvplatform.dll,*:\\Windows\\System32\\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 +TRUE,rjvplatform.dll,*:\\Windows\\SysWOW64\\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 +TRUE,rmclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rmclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rpcnsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rpcnsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rtutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtworkq.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtworkq.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rzlog4cpp_logger.dll,*\\Appdata\\local\\razer\\InGameEngine\\cache\\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia +TRUE,safestore32.dll,*:\\Program Files\\Sophos\\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf +TRUE,samcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samlib.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samlib.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sapi_onecore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sapi_onecore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sas.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sas.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scansetting.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scansetting.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scecli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scecli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,schedcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,schedcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,secur32.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,secur32.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,security.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,security.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,sensapi.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 +TRUE,sensapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 +TRUE,shell32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,shell32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,shfolder.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 +TRUE,shfolder.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 +TRUE,siteadv.dll,*:\\Program Files\\SiteAdvisor\\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf +TRUE,slc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,slc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,smadhook32c.dll,*:\\Program Files\\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,snmpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,snmpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spectrumsyncclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppcext.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,sppcext.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srmtrace.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srmtrace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srvcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srvcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ssp.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp_isv.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp_isv.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sspicli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sspicli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ssshim.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 +TRUE,ssshim.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 +TRUE,staterepository.core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,staterepository.core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,structuredquery.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,structuredquery.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sxshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sxshared.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,symsrv.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,systemsettingsthresholdadminflowui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tbs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tbs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tdh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,textshaping.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,textshaping.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,timesync.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tmdbglog.dll,*:\\Program Files\\Trend Micro\\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/ +TRUE,tosbtkbd.dll,*:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,tpmcoreprovisioning.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,tpmcoreprovisioning.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,tquery.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tquery.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tsworkspace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tsworkspace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ttdrecord.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ttdrecord.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,twext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinui.appcore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinui.appcore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uianimation.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uianimation.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uiautomationcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uiautomationcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uireng.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uireng.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uiribbon.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uiribbon.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,umpdc.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,umpdc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,unattend.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,unityplayer.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,updatepolicy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,updatepolicy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,upshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,urlmon.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,urlmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,userenv.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,userenv.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,utildll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,utildll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxinit.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxinit.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxtheme.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxtheme.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vaultcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vaultcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vdsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vdsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vender.dll,*:\\Program Files\\ASUS\\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,vender.dll,*:\\Program Files\\ASUS\\VGA COM\\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,version.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,version.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent\\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent\\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,virtdisk.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,virtdisk.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vivaldi_elf.dll,*\\Appdata\\local\\Vivaldi\\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ +TRUE,vivaldi_elf.dll,*\\Appdata\\local\\Vivaldi\\Application\\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ +TRUE,vntfxf32.dll,*:\\Program Files\\Venta\\VentaFax & Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,vsodscpl.dll,*:\\Program Files\\McAfee\\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/ +TRUE,vssapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vssapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vsstrace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vsstrace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wbemprox.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemprox.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemsvc.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemsvc.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wcmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wcmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wcnnetsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdscore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdscore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,webservices.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,webservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wecapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wecapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wer.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wer.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wevtapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wevtapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,whhelper.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,whhelper.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wimgapi.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,wimgapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,wimgapi.dll,*:\\Program Files\\Windows Kits\\10\\Assessment and Deployment Kit\\Deployment Tools\\arm64\\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,winbio.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winbio.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winbrand.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winbrand.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windows.storage.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.search.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.search.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.ui.immersive.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,windows.ui.immersive.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,windowscodecs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowscodecs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowscodecsext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowscodecsext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowsperformancerecordercontrol.dll,*:\\Program Files\\windows kits\\10\\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecordercontrol.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecordercontrol.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecorderui.dll,*:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,windowsudk.shellcommon.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowsudk.shellcommon.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winhttp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winhttp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wininet.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wininet.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winipsec.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winipsec.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmde.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winnsi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winnsi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winrnr.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winrnr.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winscard.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winscard.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winsqlite3.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsqlite3.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsta.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsta.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsync.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winsync.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winutils.dll,*:\\Program Files\\Palo Alto Networks\\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/ +TRUE,wkscli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wkscli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlanapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlanapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlancfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlancfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wldp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wldp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlidprov.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wlidprov.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiclnt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmiclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmidcom.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmidcom.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiutils.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiutils.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmpdui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmsgapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmsgapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wofutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wofutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wpdshext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wpdshext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wsc.dll,*:\\Program Files\\AVAST Software\\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2 +TRUE,wscapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wscapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wsdapi.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,wsdapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,wshbth.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wshbth.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wshelper.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wshelper.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wsmsvc.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wsmsvc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wtsapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wtsapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwancfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwancfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xmllite.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xmllite.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xolehlp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xolehlp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xpsservices.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,xpsservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,xwizards.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwizards.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwtpw32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwtpw32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables diff --git a/lookups/csv/hijacklibs_loaded.yml b/lookups/csv/hijacklibs_loaded.yml index 866fe9c35c4..425e4b75ac8 100644 --- a/lookups/csv/hijacklibs_loaded.yml +++ b/lookups/csv/hijacklibs_loaded.yml @@ -1,8 +1,8 @@ name: hijacklibs_loaded id: 0a58a703-3a7a-4b27-a82b-f5a61acd3f1a -version: 4 +version: 5 creation_date: '2021-07-12' -modification_date: '2026-05-13' +modification_date: '2026-09-29' author: Splunk Threat Research Team lookup_type: csv description: A list of potentially abused libraries in Windows From bd1c4cb04fb4fc5567fcd00adac1e5656d16df06 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Wed, 30 Sep 2026 12:04:30 +0200 Subject: [PATCH 07/10] revert csv changes --- lookups/csv/hijacklibs_loaded.csv | 1772 ++++++++++++++--------------- lookups/csv/hijacklibs_loaded.yml | 4 +- 2 files changed, 888 insertions(+), 888 deletions(-) diff --git a/lookups/csv/hijacklibs_loaded.csv b/lookups/csv/hijacklibs_loaded.csv index cb93a27993b..3a14253534b 100644 --- a/lookups/csv/hijacklibs_loaded.csv +++ b/lookups/csv/hijacklibs_loaded.csv @@ -1,887 +1,887 @@ islibrary,library,excludes,ttp,comment -TRUE,aclui.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,aclui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,acrodistdll.dll,*:\\Program Files\\Adobe\\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf -TRUE,acrodistdll.dll,*\\Acrobat\\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf -TRUE,activeds.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,activeds.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,adsldpc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,adsldpc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,aepic.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,aepic.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,apphelp.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,apphelp.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,applicationframe.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,applicationframe.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,appvpolicy.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,appwiz.cpl,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ -TRUE,appwiz.cpl,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ -TRUE,appxalluserstore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxalluserstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxdeploymentclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,appxdeploymentclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,archiveint.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,archiveint.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ashldres.dll,*:\\Program Files\\McAfee.com\\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf -TRUE,atl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,atl.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,atltracetoolui.dll,*:\\Program Files\\Microsoft Visual Studio 11.0\\Common7\\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,audioses.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,audioses.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,auditpolcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,auditpolcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authfwcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authfwcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authz.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,authz.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,avrt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,avrt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,basicnetutils.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,basicnetutils.dll,*:\\Program Files\\BAIDU\\BAIDUPINYIN\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,batmeter.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,batmeter.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,bcd.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcd.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47langs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47langs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47mrm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcp47mrm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bcrypt.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,bcrypt.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,bderepair.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bootmenuux.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,bootux.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cabinet.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cabinet.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cabview.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cabview.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,certcli.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,certcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,certenroll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,certenroll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cfgmgr32.dll,*:\\Windows\\System32\\*,T1574.002, -TRUE,cfgmgr32.dll,*:\\Windows\\SysWOW64\\*,T1574.002, -TRUE,chrome_frame_helper.dll,*\\Appdata\\local\\Google\\Chrome\\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,chrome_frame_helper.dll,*:\\Program Files\\Google\\Chrome\\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ -TRUE,ciscosparklauncher.dll,*\\Appdata\\local\\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,ciscosparklauncher.dll,*\\AppData\\Local\\Programs\\Cisco Spark\\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,classicexplorer32.dll,*:\\Program Files\\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets -TRUE,classicexplorer32.dll,*:\\Program Files\\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets -TRUE,cldapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cldapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clipc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clipc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clusapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,clusapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmpbk32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmpbk32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cmutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cmutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coloradapterclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coloradapterclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,colorui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,colorui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,comdlg32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,comdlg32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,commfunc.dll,*:\\Program Files\\Lenovo\\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,configmanager2.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,connect.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,connect.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,coredplus.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coremessaging.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coremessaging.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,coreuicomponents.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,coreuicomponents.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,credui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,credui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptbase.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptdll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptdll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptsp.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cryptsp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,cryptui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptxml.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cryptxml.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,cscobj.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscobj.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscui.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,cscui.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,d2d1.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d2d1.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10_1core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10warp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d10warp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d11.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d11.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d12.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d12.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d9.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3d9.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\bin\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\bin\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\redist\\d3d\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\windows kits\\10\\redist\\d3d\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\cisco systems\\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\microsoft\\edge\\application\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Program Files\\Google\\Chrome\\Application\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\\Appdata\\local\\microsoft\\teams\\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dcompiler_47.dll,*\\Microsoft\\Teams\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,d3dx9_43.dll,*:\\Windows\\System32\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,d3dx9_43.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,dataexchange.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dataexchange.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,davclnt.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,davclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Program Files\\microsoft office\\root\\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbgeng.dll,*:\\Program Files\\Windows Kits\\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\arm64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x64\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\windows kits\\10\\debuggers\\x86\\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\cisco systems\\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\microsoft office\\root\\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Program Files\\microsoft office\\root\\vfs\\programfilesx86\\microsoft analysis services\\as oledb\\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbghelp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dbgmodel.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dbgmodel.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dbgmodel.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,dcntel.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dcomp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dcomp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,defragproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,defragproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,desktopshellext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,desktopshellext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,deviceassociation.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,deviceassociation.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicecredential.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicecredential.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devicepairing.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,devicepairing.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,devobj.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devobj.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devrtl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,devrtl.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcmonitor.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcmonitor.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc6.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dhcpcsvc6.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,directmanipulation.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,directmanipulation.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,dismapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dismapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dismcore.dll,*:\\Windows\\System32\\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ -TRUE,dismcore.dll,*:\\Windows\\SysWOW64\\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ -TRUE,dmcfgutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcfgutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcmnutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcmnutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmcommandlineutils.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dmcommandlineutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dmenrollengine.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmenrollengine.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmenterprisediagnostics.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmiso8601utils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmiso8601utils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmoleaututils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmoleaututils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmprocessxmlfiltered.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmprocessxmlfiltered.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmpushproxy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmpushproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmxmlhelputils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dmxmlhelputils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dnsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dnsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3api.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3api.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3cfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dot3cfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dpx.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dpx.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,drprov.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,drprov.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,drvstore.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,drvstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsparse.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsparse.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsprop.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsprop.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dsreg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsreg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsrole.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dsrole.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dui70.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dui70.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,duser.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,duser.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dusmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dusmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwmcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwrite.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dwrite.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxcore.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dxcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,dxgi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxgi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxva2.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dxva2.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,dynamoapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappprxy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,eappprxy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,edgeiso.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,edgeiso.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,edputil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,edputil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsadu.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsadu.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,efsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,esent.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,esent.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,execmodelproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,execmodelproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,explorerframe.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,explorerframe.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,facesdk.dll,*:\\Program Files\\luxand\\facesdk\\bin\\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,fastprox.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fastprox.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,faultrep.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,faultrep.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fddevquery.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fddevquery.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,feclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,feclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fhcfg.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fhcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fhsvcctl.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,firewallapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,firewallapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,flightsettings.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,flightsettings.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,fltlib.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fltlib.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,formdll.dll,*:\\Program Files\\Common Files\\Microsoft Shared\\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1 -TRUE,framedynos.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,framedynos.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fveapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fveapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fveskybackup.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fvewiz.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,fwbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwbase.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwcfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwcfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpolicyiomgr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpolicyiomgr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpuclnt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fwpuclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*:\\Windows\\System32\\driverstore\\filerepository\\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxsst.dll,*:\\Windows\\System32\\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/ -TRUE,fxstiff.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,fxstiff.dll,*:\\Windows\\System32\\driverstore\\filerepository\\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,getuname.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,getuname.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,gflagsui.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,glib-2.0.dll,*:\\Program Files\\VMware\\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ -TRUE,gpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,gpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,hha.dll,*:\\Windows\\System32\\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hha.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hha.dll,*:\\Program Files\\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ -TRUE,hid.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hid.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hnetmon.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hnetmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,hpcustpartui.dll,*:\\Program Files\\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html -TRUE,hpqhvsei.dll,*:\\Program Files\\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,httpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,httpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,icmp.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,icmp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,idstore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,idstore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ieadvpack.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ieadvpack.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iedkcs32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iedkcs32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iernonce.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ -TRUE,iernonce.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ -TRUE,iertutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iertutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifmon.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ifsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,ifsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,inproclogger.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iphlpapi.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iphlpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iri.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iri.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsidsc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsidsc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsiexe.dll,*:\\Windows\\System32\\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC -TRUE,iscsiexe.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC -TRUE,iscsium.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iscsium.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,isv.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,isv.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,iumbase.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,iumsdk.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,iviewers.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,joinutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,joinutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,kdstub.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ksuser.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ksuser.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ktmw32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ktmw32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ldvpocx.ocx,*:\\Program Files\\Symantec_Client_Security\\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox -TRUE,ldvpocx.ocx,*:\\Program Files\\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox -TRUE,libcares-2.dll,*\\git\\mingw64\\*,T1574.002,https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/ -TRUE,libvlc.dll,*:\\Program Files\\VideoLAN\\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ -TRUE,licensemanagerapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,licensemanagerapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,licensingdiagspp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,licensingdiagspp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,linkinfo.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,linkinfo.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn\\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,lmiguardiandll.dll,*:\\Program Files\\LogMeIn\\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 -TRUE,loadperf.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,loadperf.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,lockdown.dll,*:\\Program Files\\McAfee\\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600 -TRUE,lockhostingframework.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,log.dll,*:\\Program Files\\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,logoncli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,logoncli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,logoncontroller.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,logoncontroller.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lpksetupproxyserv.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lpksetupproxyserv.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,lrwizdll.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,magnification.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,magnification.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,maintenanceui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mapistub.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mapistub.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mbaexmlparser.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mdmdiagnostics.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfc42u.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mfc42u.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,mfcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfplat.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mfplat.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,midimap.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,midimap.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mintdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,miutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,miutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mlang.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mlang.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mmdevapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mmdevapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mobilenetworking.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mobilenetworking.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mozglue.dll,*:\\Program Files\\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*:\\Program Files\\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*:\\Program Files\\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mozglue.dll,*\\AppData\\Local\\Mozilla Firefox\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mpclient.dll,*:\\Program Files\\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ -TRUE,mpclient.dll,*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ -TRUE,mpr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mpr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mprapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mprapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mpsvc.dll,*:\\Program Files\\Windows Defender\\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ -TRUE,mpsvc.dll,*\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ -TRUE,mrmcorer.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mrmcorer.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msacm32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msacm32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscms.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscms.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscoree.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscoree.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mscorsvc.dll,*:\\Windows\\Microsoft.NET\\Framework\\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,mscorsvc.dll,*:\\Windows\\Microsoft.NET\\Framework64\\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,msctf.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msctf.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msctfmonitor.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msctfmonitor.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdrm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdrm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msdtctm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msftedit.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,msftedit.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,msi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msiso.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msiso.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msutb.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msutb.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,msvcp110_win.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msvcp110_win.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,msvcr100.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,msvcr100.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,mswb7.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswb7.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswsock.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mswsock.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msxml3.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,msxml3.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,mtxclu.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,mtxclu.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,napinsp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,napinsp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ncrypt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ncrypt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ndfapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ndfapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netid.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netid.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netiohlp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netiohlp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netjoin.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netjoin.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netplwiz.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netplwiz.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netprofm.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netprofm.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netprovfw.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netprovfw.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,netsetupapi.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netsetupapi.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,netshell.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netshell.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nettrace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,netutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,networkexplorer.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,networkexplorer.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,newdev.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,newdev.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ninput.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ninput.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlaapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlaapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nlansp_c.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nlansp_c.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,npmproxy.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,npmproxy.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nshhttp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshhttp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshipsec.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshipsec.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshwfp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,nshwfp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntdsapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntdsapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntlanman.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntlanman.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntlmshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntlmshared.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ntmarta.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntmarta.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntshrui.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ntshrui.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,nvsmartmax.dll,*:\\Program Files\\NVIDIA Corporation\\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos -TRUE,oleacc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,oleacc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,omadmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,omadmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,onex.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,onex.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,opcservices.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,opcservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,opera_elf.dll,*\\Appdata\\local\\programs\\opera\\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412 -TRUE,osbaseln.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osbaseln.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osksupport.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osuninst.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,osuninst.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,outllib.dll,*:\\Program Files\\Microsoft Office\\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 -TRUE,outllib.dll,*:\\Program Files\\Microsoft Office\\Root\\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 -TRUE,p2p.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2p.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2pnetsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p2pnetsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,p9np.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,p9np.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pcaui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pcaui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pdh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,peerdistsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,peerdistsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,pkeyhelper.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,pla.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pla.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,playsndsrv.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,playsndsrv.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,pnrpnsp.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,pnrpnsp.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,policymanager.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,policymanager.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,polstore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,polstore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,powrprof.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,powrprof.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,printui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,printui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,prntvpt.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,prntvpt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,profapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,profapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,propsys.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,propsys.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,proximitycommon.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,proximitycommon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,proximityservicepal.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,prvdmofcomp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,prvdmofcomp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,puiapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,puiapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,python39.dll,*:\\Program Files\\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\VC\\SecurityIssueAnalysis\\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,python39.dll,*\\Users\\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 -TRUE,qrt.dll,*:\\Program Files\\F-Secure\\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/ -TRUE,radcui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,radcui.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasdlg.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,rasdlg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,rasgcw.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rasgcw.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rasman.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasman.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasmontr.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rasmontr.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rastls.dll,*:\\Program Files\\Symantec\\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf -TRUE,rcdll.dll,*:\\Program Files\\Windows Kits\\10\\bin\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,reagent.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,reagent.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,regapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,regapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,reseteng.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resetengine.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,resutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rjvplatform.dll,*:\\Windows\\System32\\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 -TRUE,rjvplatform.dll,*:\\Windows\\SysWOW64\\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 -TRUE,rmclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rmclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rpcnsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rpcnsh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,rtutils.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtutils.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtworkq.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rtworkq.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,rzlog4cpp_logger.dll,*\\Appdata\\local\\razer\\InGameEngine\\cache\\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia -TRUE,safestore32.dll,*:\\Program Files\\Sophos\\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf -TRUE,samcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samlib.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,samlib.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sapi_onecore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sapi_onecore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sas.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sas.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scansetting.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scansetting.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scecli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,scecli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,schedcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,schedcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,secur32.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,secur32.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,security.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,security.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,sensapi.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 -TRUE,sensapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 -TRUE,shell32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,shell32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,shfolder.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 -TRUE,shfolder.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 -TRUE,siteadv.dll,*:\\Program Files\\SiteAdvisor\\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf -TRUE,slc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,slc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,smadhook32c.dll,*:\\Program Files\\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,snmpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,snmpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spectrumsyncclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,spp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppc.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sppcext.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,sppcext.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srclient.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srclient.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srmtrace.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srmtrace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,srpapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srpapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srvcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,srvcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ssp.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp_isv.exe_rsaenh.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,ssp_isv.exe_rsaenh.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sspicli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sspicli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ssshim.dll,*:\\Windows\\System32\\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 -TRUE,ssshim.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 -TRUE,staterepository.core.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,staterepository.core.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,structuredquery.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,structuredquery.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,sxshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,sxshared.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,symsrv.dll,*:\\Program Files\\Windows Kits\\10\\Debuggers\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,systemsettingsthresholdadminflowui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tbs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tbs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tdh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tdh.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,textshaping.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,textshaping.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,timesync.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tmdbglog.dll,*:\\Program Files\\Trend Micro\\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/ -TRUE,tosbtkbd.dll,*:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis -TRUE,tpmcoreprovisioning.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,tpmcoreprovisioning.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,tquery.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tquery.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tsworkspace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,tsworkspace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ttdrecord.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,ttdrecord.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,twext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinui.appcore.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,twinui.appcore.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uianimation.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uianimation.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uiautomationcore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uiautomationcore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uireng.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uireng.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uiribbon.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,uiribbon.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,umpdc.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,umpdc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,unattend.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,unityplayer.dll,*\\Appdata\\local\\Temp\\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ -TRUE,updatepolicy.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,updatepolicy.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,upshared.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,urlmon.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,urlmon.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,userenv.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,userenv.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,utildll.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,utildll.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxinit.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxinit.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxtheme.dll,*:\\Windows\\System32\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,uxtheme.dll,*:\\Windows\\SysWOW64\\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vaultcli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vaultcli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vdsutil.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vdsutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vender.dll,*:\\Program Files\\ASUS\\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,vender.dll,*:\\Program Files\\ASUS\\VGA COM\\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,version.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,version.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent\\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent\\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,vftrace.dll,*:\\Program Files\\CyberArk\\Endpoint Privilege Manager\\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true -TRUE,virtdisk.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,virtdisk.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vivaldi_elf.dll,*\\Appdata\\local\\Vivaldi\\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ -TRUE,vivaldi_elf.dll,*\\Appdata\\local\\Vivaldi\\Application\\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ -TRUE,vntfxf32.dll,*:\\Program Files\\Venta\\VentaFax & Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ -TRUE,vsodscpl.dll,*:\\Program Files\\McAfee\\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/ -TRUE,vssapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vssapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vsstrace.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,vsstrace.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wbemprox.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemprox.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemsvc.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wbemsvc.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wcmapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wcmapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wcnnetsh.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdscore.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wdscore.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,webservices.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,webservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wecapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wecapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wer.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wer.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wevtapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wevtapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,whhelper.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,whhelper.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wimgapi.dll,*:\\Windows\\System32\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,wimgapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,wimgapi.dll,*:\\Program Files\\Windows Kits\\10\\Assessment and Deployment Kit\\Deployment Tools\\arm64\\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ -TRUE,winbio.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winbio.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winbrand.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winbrand.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windows.storage.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.search.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.storage.search.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windows.ui.immersive.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,windows.ui.immersive.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,windowscodecs.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowscodecs.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowscodecsext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowscodecsext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowsperformancerecordercontrol.dll,*:\\Program Files\\windows kits\\10\\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecordercontrol.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecordercontrol.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,windowsperformancerecorderui.dll,*:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,windowsudk.shellcommon.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,windowsudk.shellcommon.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winhttp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winhttp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wininet.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wininet.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winipsec.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winipsec.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmde.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmm.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winmm.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winnsi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winnsi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winrnr.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winrnr.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,winscard.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winscard.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winsqlite3.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsqlite3.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsta.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsta.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,winsync.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winsync.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,winutils.dll,*:\\Program Files\\Palo Alto Networks\\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/ -TRUE,wkscli.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wkscli.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlanapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlanapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlancfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlancfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wldp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wldp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wlidprov.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wlidprov.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiclnt.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmiclnt.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmidcom.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmidcom.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiutils.dll,*:\\Windows\\System32\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmiutils.dll,*:\\Windows\\SysWOW64\\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wmpdui.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmsgapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wmsgapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wofutil.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wofutil.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wpdshext.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wpdshext.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wsc.dll,*:\\Program Files\\AVAST Software\\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2 -TRUE,wscapi.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wscapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wsdapi.dll,*:\\Windows\\System32\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,wsdapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ -TRUE,wshbth.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wshbth.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,wshelper.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wshelper.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wsmsvc.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wsmsvc.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,wtsapi32.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wtsapi32.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwancfg.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwancfg.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwapi.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,wwapi.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xmllite.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xmllite.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xolehlp.dll,*:\\Windows\\System32\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xolehlp.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows -TRUE,xpsservices.dll,*:\\Windows\\System32\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,xpsservices.dll,*:\\Windows\\SysWOW64\\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ -TRUE,xwizards.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwizards.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwtpw32.dll,*:\\Windows\\System32\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables -TRUE,xwtpw32.dll,*:\\Windows\\SysWOW64\\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,aclui.dll,*:\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,aclui.dll,*:\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,acrodistdll.dll,*:\Program Files\Adobe\Acrobat *,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf +TRUE,acrodistdll.dll,*\Acrobat\acrodistdll*,T1574.002,https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf +TRUE,activeds.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,activeds.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,adsldpc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,adsldpc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,aepic.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,aepic.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,apphelp.dll,*:\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,apphelp.dll,*:\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,applicationframe.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,applicationframe.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,appvpolicy.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,appwiz.cpl,*:\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ +TRUE,appwiz.cpl,*:\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ +TRUE,appxalluserstore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxalluserstore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxdeploymentclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,appxdeploymentclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,archiveint.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,archiveint.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ashldres.dll,*:\Program Files\McAfee.com\VSO*,T1574.002,https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf +TRUE,atl.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,atl.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,atltracetoolui.dll,*:\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,audioses.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,audioses.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,auditpolcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,auditpolcore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authfwcfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authfwcfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authz.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,authz.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,avrt.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,avrt.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,basicnetutils.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,basicnetutils.dll,*:\Program Files\BAIDU\BAIDUPINYIN\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,batmeter.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,batmeter.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,bcd.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcd.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47langs.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47langs.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47mrm.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcp47mrm.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bcrypt.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,bcrypt.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,bderepair.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bootmenuux.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,bootux.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cabinet.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cabinet.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cabview.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cabview.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,certcli.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,certcli.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,certenroll.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,certenroll.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cfgmgr32.dll,*:\Windows\System32\*,T1574.002, +TRUE,cfgmgr32.dll,*:\Windows\SysWOW64\*,T1574.002, +TRUE,chrome_frame_helper.dll,*\Appdata\local\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,chrome_frame_helper.dll,*:\Program Files\Google\Chrome\Application*,T1574.002,https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ +TRUE,ciscosparklauncher.dll,*\Appdata\local\CiscoSparkLauncher*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,ciscosparklauncher.dll,*\AppData\Local\Programs\Cisco Spark\*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,classicexplorer32.dll,*:\Program Files\Classic Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets +TRUE,classicexplorer32.dll,*:\Program Files\Open-Shell*,T1574.002,https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets +TRUE,cldapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cldapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clipc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clipc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clusapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,clusapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmpbk32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmpbk32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cmutil.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cmutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coloradapterclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coloradapterclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,colorui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,colorui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,comdlg32.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,comdlg32.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,commfunc.dll,*:\Program Files\Lenovo\Communications Utility*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,configmanager2.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,connect.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,connect.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,coredplus.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coremessaging.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coremessaging.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,coreuicomponents.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,coreuicomponents.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,credui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,credui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptbase.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptbase.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptdll.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptdll.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptsp.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cryptsp.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,cryptui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptxml.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cryptxml.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,cscobj.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscobj.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscui.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,cscui.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,d2d1.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d2d1.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1core.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10_1core.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10core.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10core.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10warp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d10warp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d11.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d11.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d12.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d12.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d9.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3d9.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\windows kits\10\bin\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\windows kits\10\redist\d3d\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\windows kits\10\redist\d3d\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\wireshark*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\microsoft\edge\application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Program Files\Google\Chrome\Application\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*\Appdata\local\microsoft\teams\stage*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dcompiler_47.dll,*\Microsoft\Teams\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,d3dx9_43.dll,*:\Windows\System32\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,d3dx9_43.dll,*:\Windows\SysWOW64\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,dataexchange.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dataexchange.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,davclnt.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,davclnt.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgcore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgeng.dll,*:\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbgeng.dll,*:\Program Files\Windows Kits\*,T1574.002,https://twitter.com/mrexodia/status/1630320327967252483 +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\arm*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\arm\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\arm64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\arm64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\x64*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\x64\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\x86*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\windows kits\10\debuggers\x86\srcsrv*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\cisco systems\cisco jabber*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\microsoft office\root\office*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbghelp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dbgmodel.dll,*:\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dbgmodel.dll,*:\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dbgmodel.dll,*:\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,dcntel.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dcomp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dcomp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,defragproxy.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,defragproxy.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,desktopshellext.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,desktopshellext.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,deviceassociation.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,deviceassociation.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicecredential.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicecredential.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devicepairing.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,devicepairing.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,devobj.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devobj.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devrtl.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,devrtl.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcmonitor.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcmonitor.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc6.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dhcpcsvc6.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,directmanipulation.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,directmanipulation.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,dismapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dismapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dismcore.dll,*:\Windows\System32\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ +TRUE,dismcore.dll,*:\Windows\SysWOW64\dism*,T1574.001,https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ +TRUE,dmcfgutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcfgutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcmnutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcmnutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmcommandlineutils.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dmcommandlineutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dmenrollengine.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmenrollengine.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmenterprisediagnostics.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmiso8601utils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmiso8601utils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmoleaututils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmoleaututils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmprocessxmlfiltered.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmprocessxmlfiltered.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmpushproxy.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmpushproxy.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmxmlhelputils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dmxmlhelputils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dnsapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dnsapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3api.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3api.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3cfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dot3cfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dpx.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dpx.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,drprov.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,drprov.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,drvstore.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,drvstore.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsparse.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsparse.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsprop.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsprop.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dsreg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsreg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsrole.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dsrole.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dui70.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dui70.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,duser.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,duser.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dusmapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dusmapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwmcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwrite.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dwrite.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxcore.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dxcore.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,dxgi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxgi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxva2.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dxva2.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,dynamoapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappcfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappcfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappprxy.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,eappprxy.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,edgeiso.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,edgeiso.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,edputil.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,edputil.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsadu.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsadu.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsutil.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,efsutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,esent.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,esent.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,execmodelproxy.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,execmodelproxy.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,explorerframe.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,explorerframe.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,facesdk.dll,*:\Program Files\luxand\facesdk\bin\win64*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,fastprox.dll,*:\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fastprox.dll,*:\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,faultrep.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,faultrep.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fddevquery.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fddevquery.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,feclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,feclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fhcfg.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fhcfg.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fhsvcctl.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,firewallapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,firewallapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,flightsettings.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,flightsettings.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,fltlib.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fltlib.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,formdll.dll,*:\Program Files\Common Files\Microsoft Shared\NoteSync Forms*,T1574.002,https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1 +TRUE,framedynos.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,framedynos.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fveapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fveapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fveskybackup.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fvewiz.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,fwbase.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwbase.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwcfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwcfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpolicyiomgr.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpolicyiomgr.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpuclnt.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fwpuclnt.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxsst.dll,*:\Windows\System32\*,T1574.001,https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/ +TRUE,fxstiff.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,fxstiff.dll,*:\Windows\System32\driverstore\filerepository\prnms002.inf_*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,getuname.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,getuname.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,gflagsui.dll,*:\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,glib-2.0.dll,*:\Program Files\VMware\VMware Tools*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,glib-2.0.dll,*:\Program Files\VMware\VMware Workstation*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,glib-2.0.dll,*:\Program Files\VMware\VMware Player*,T1574.002,https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ +TRUE,gpapi.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,gpapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,hha.dll,*:\Windows\System32\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hha.dll,*:\Windows\SysWOW64\*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hha.dll,*:\Program Files\HTML Help Workshop*,T1574.002,https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ +TRUE,hid.dll,*:\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hid.dll,*:\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hnetmon.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hnetmon.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,hpcustpartui.dll,*:\Program Files\HP*,T1574.002,https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html +TRUE,hpqhvsei.dll,*:\Program Files\HP*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,httpapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,httpapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,icmp.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,icmp.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,idstore.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,idstore.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ieadvpack.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ieadvpack.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iedkcs32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iedkcs32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iernonce.dll,*:\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ +TRUE,iernonce.dll,*:\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ +TRUE,iertutil.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iertutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifmon.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifmon.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ifsutil.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,ifsutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,inproclogger.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iphlpapi.dll,*:\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iphlpapi.dll,*:\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iri.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iri.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsidsc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsidsc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsiexe.dll,*:\Windows\System32\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC +TRUE,iscsiexe.dll,*:\Windows\SysWOW64\*,T1574.001,https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC +TRUE,iscsium.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iscsium.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,isv.exe_rsaenh.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,isv.exe_rsaenh.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,iumbase.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,iumsdk.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,iviewers.dll,*:\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,iviewers.dll,*:\Program Files\Windows Kits\10\bin\*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,joinutil.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,joinutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,kdstub.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ksuser.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ksuser.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ktmw32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ktmw32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ldvpocx.ocx,*:\Program Files\Symantec_Client_Security\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox +TRUE,ldvpocx.ocx,*:\Program Files\Symantec AntiVirus*,T1574.002,https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox +TRUE,libcares-2.dll,*\git\mingw64\*,T1574.002,https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/ +TRUE,libvlc.dll,*:\Program Files\VideoLAN\VLC*,T1574.002,https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ +TRUE,licensemanagerapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,licensemanagerapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,licensingdiagspp.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,licensingdiagspp.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,linkinfo.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,linkinfo.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,lmiguardiandll.dll,*:\Program Files\LogMeIn*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,lmiguardiandll.dll,*:\Program Files\LogMeIn\x86*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,lmiguardiandll.dll,*:\Program Files\LogMeIn\x64*,T1574.002,https://twitter.com/StopMalvertisin/status/1610961056163311619 +TRUE,loadperf.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,loadperf.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,lockdown.dll,*:\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://twitter.com/thepacketrat/status/1520878930449817600 +TRUE,lockhostingframework.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,log.dll,*:\Program Files\Bitdefender Antivirus Free*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,logoncli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,logoncli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,logoncontroller.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,logoncontroller.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lpksetupproxyserv.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lpksetupproxyserv.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,lrwizdll.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,magnification.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,magnification.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,maintenanceui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mapistub.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mapistub.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mbaexmlparser.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mdmdiagnostics.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfc42u.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mfc42u.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,mfcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfcore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfplat.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mfplat.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,midimap.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,midimap.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mintdh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,miutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,miutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mlang.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mlang.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mmdevapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mmdevapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mobilenetworking.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mobilenetworking.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mozglue.dll,*:\Program Files\SeaMonkey*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*:\Program Files\Mozilla Firefox*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*:\Program Files\Mozilla Thunderbird*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mozglue.dll,*\AppData\Local\Mozilla Firefox\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mpclient.dll,*:\Program Files\Windows Defender*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ +TRUE,mpclient.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ +TRUE,mpr.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mpr.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mprapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mprapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mpsvc.dll,*:\Program Files\Windows Defender\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ +TRUE,mpsvc.dll,*\ProgramData\Microsoft\Windows Defender\Platform\*,T1574.002,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ +TRUE,mrmcorer.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mrmcorer.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msacm32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msacm32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscms.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscms.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscoree.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscoree.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mscorsvc.dll,*:\Windows\Microsoft.NET\Framework\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,mscorsvc.dll,*:\Windows\Microsoft.NET\Framework64\v*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,msctf.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msctf.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msctfmonitor.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msctfmonitor.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdrm.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdrm.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msdtctm.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msftedit.dll,*:\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,msftedit.dll,*:\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,msi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msiso.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msiso.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msutb.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msutb.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,msvcp110_win.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msvcp110_win.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,msvcr100.dll,*:\Windows\System32\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,msvcr100.dll,*:\Windows\SysWOW64\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,mswb7.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswb7.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswsock.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mswsock.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msxml3.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,msxml3.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,mtxclu.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,mtxclu.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,napinsp.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,napinsp.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ncrypt.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ncrypt.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ndfapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ndfapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netapi32.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netapi32.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netid.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netid.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netiohlp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netiohlp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netjoin.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netjoin.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netplwiz.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netplwiz.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netprofm.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netprofm.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netprovfw.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netprovfw.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,netsetupapi.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netsetupapi.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,netshell.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netshell.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nettrace.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,netutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,networkexplorer.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,networkexplorer.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,newdev.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,newdev.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ninput.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ninput.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlaapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlaapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nlansp_c.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nlansp_c.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,npmproxy.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,npmproxy.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nshhttp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshhttp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshipsec.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshipsec.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshwfp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,nshwfp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntdsapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntdsapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntlanman.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntlanman.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntlmshared.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntlmshared.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ntmarta.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntmarta.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntshrui.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ntshrui.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,nvsmartmax.dll,*:\Program Files\NVIDIA Corporation\Display*,T1574.002,https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos +TRUE,oleacc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,oleacc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,omadmapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,omadmapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,onex.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,onex.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,opcservices.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,opcservices.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,opera_elf.dll,*\Appdata\local\programs\opera\*,T1574.002,https://twitter.com/ShitSecure/status/1566127363389329412 +TRUE,osbaseln.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osbaseln.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osksupport.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osuninst.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,osuninst.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,outllib.dll,*:\Program Files\Microsoft Office\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 +TRUE,outllib.dll,*:\Program Files\Microsoft Office\Root\OFFICE*,T1574.002,https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 +TRUE,p2p.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2p.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2pnetsh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p2pnetsh.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,p9np.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,p9np.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pcaui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pcaui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pdh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pdh.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,peerdistsh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,peerdistsh.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,pkeyhelper.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,pla.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pla.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,playsndsrv.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,playsndsrv.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,pnrpnsp.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,pnrpnsp.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,policymanager.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,policymanager.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,polstore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,polstore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,powrprof.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,powrprof.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,printui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,printui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,prntvpt.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,prntvpt.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,profapi.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,profapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,propsys.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,propsys.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,proximitycommon.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,proximitycommon.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,proximityservicepal.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,prvdmofcomp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,prvdmofcomp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,puiapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,puiapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,python39.dll,*:\Program Files\Python39*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*\Appdata\local\Temp\*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*:\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,python39.dll,*\Users\anaconda3*,T1574.002,https://twitter.com/SBousseaden/status/1530595156055011330 +TRUE,qrt.dll,*:\Program Files\F-Secure\Anti-Virus*,T1574.002,https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/ +TRUE,radcui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,radcui.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasapi32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasapi32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasdlg.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,rasdlg.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,rasgcw.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rasgcw.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rasman.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasman.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasmontr.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rasmontr.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rastls.dll,*:\Program Files\Symantec\Network Connected Devices Auto Setup*,T1574.002,https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf +TRUE,rcdll.dll,*:\Program Files\Windows Kits\10\bin\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,reagent.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,reagent.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,regapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,regapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,reseteng.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resetengine.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,resutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rjvplatform.dll,*:\Windows\System32\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 +TRUE,rjvplatform.dll,*:\Windows\SysWOW64\SystemResetPlatform*,T1574.002,https://twitter.com/0gtweet/status/1666716511988330499 +TRUE,rmclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rmclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rpcnsh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rpcnsh.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rsaenh.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rsaenh.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,rtutils.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtutils.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtworkq.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rtworkq.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,rzlog4cpp_logger.dll,*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*,T1574.002,https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia +TRUE,safestore32.dll,*:\Program Files\Sophos\Sophos Anti-Virus*,T1574.002,https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf +TRUE,samcli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samcli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samlib.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,samlib.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sapi_onecore.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sapi_onecore.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sas.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sas.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scansetting.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scansetting.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scecli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,scecli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,schedcli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,schedcli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,secur32.dll,*:\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,secur32.dll,*:\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,security.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,security.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,sensapi.dll,*:\Windows\System32\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 +TRUE,sensapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://twitter.com/AndrewOliveau/status/1682185200862625792 +TRUE,shell32.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,shell32.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,shfolder.dll,*:\Windows\System32\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 +TRUE,shfolder.dll,*:\Windows\SysWOW64\*,T1574.002,https://twitter.com/dissectmalware/status/978017957480628226 +TRUE,siteadv.dll,*:\Program Files\SiteAdvisor\*,T1574.002,https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf +TRUE,slc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,slc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,smadhook32c.dll,*:\Program Files\Smadav*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,snmpapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,snmpapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spectrumsyncclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,spp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppc.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppc.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sppcext.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,sppcext.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srclient.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srclient.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srmtrace.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srmtrace.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,srpapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srpapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srvcli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,srvcli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ssp.exe_rsaenh.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp.exe_rsaenh.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp_isv.exe_rsaenh.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,ssp_isv.exe_rsaenh.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sspicli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sspicli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ssshim.dll,*:\Windows\System32\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 +TRUE,ssshim.dll,*:\Windows\SysWOW64\*,T1574.002,https://twitter.com/0gtweet/status/1363107343018385410 +TRUE,staterepository.core.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,staterepository.core.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,structuredquery.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,structuredquery.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,sxshared.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,sxshared.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,symsrv.dll,*:\Program Files\Windows Kits\10\Debuggers\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,systemsettingsthresholdadminflowui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tapi32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tapi32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tbs.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tbs.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tdh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tdh.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,textshaping.dll,*:\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,textshaping.dll,*:\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,timesync.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tmdbglog.dll,*:\Program Files\Trend Micro\Titanium*,T1574.002,https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/ +TRUE,tosbtkbd.dll,*:\Program Files\Toshiba\Bluetooth Toshiba Stack*,T1574.002,https://www.secureworks.com/research/shadowpad-malware-analysis +TRUE,tpmcoreprovisioning.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,tpmcoreprovisioning.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,tquery.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tquery.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tsworkspace.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,tsworkspace.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ttdrecord.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,ttdrecord.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,twext.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twext.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinui.appcore.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,twinui.appcore.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uianimation.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uianimation.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uiautomationcore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uiautomationcore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uireng.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uireng.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uiribbon.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,uiribbon.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,umpdc.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,umpdc.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,unattend.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,unityplayer.dll,*\Appdata\local\Temp\*,T1574.002,https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ +TRUE,updatepolicy.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,updatepolicy.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,upshared.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,urlmon.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,urlmon.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,userenv.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,userenv.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,utildll.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,utildll.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxinit.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxinit.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxtheme.dll,*:\Windows\System32\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,uxtheme.dll,*:\Windows\SysWOW64\*,T1574.001,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vaultcli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vaultcli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vdsutil.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vdsutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vender.dll,*:\Program Files\ASUS\GPU TweakII*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,vender.dll,*:\Program Files\ASUS\VGA COM\*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,version.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,version.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,vftrace.dll,*:\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,vftrace.dll,*:\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,vftrace.dll,*:\Program Files\CyberArk\Endpoint Privilege Manager\Agent*,T1574.002,https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true +TRUE,virtdisk.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,virtdisk.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ +TRUE,vivaldi_elf.dll,*\Appdata\local\Vivaldi\Application\*,T1574.002,https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ +TRUE,vntfxf32.dll,*:\Program Files\Venta\VentaFax & Voice*,T1574.002,https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ +TRUE,vsodscpl.dll,*:\Program Files\McAfee\VirusScan Enterprise*,T1574.002,https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/ +TRUE,vssapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vssapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vsstrace.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,vsstrace.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wbemprox.dll,*:\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemprox.dll,*:\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemsvc.dll,*:\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wbemsvc.dll,*:\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wcmapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wcmapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wcnnetsh.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdscore.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wdscore.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,webservices.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,webservices.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wecapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wecapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wer.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wer.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wevtapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wevtapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,whhelper.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,whhelper.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wimgapi.dll,*:\Windows\System32\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,wimgapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,wimgapi.dll,*:\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*,T1574.002,https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ +TRUE,winbio.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winbio.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winbrand.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winbrand.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windows.storage.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.search.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.storage.search.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windows.ui.immersive.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,windows.ui.immersive.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,windowscodecs.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowscodecs.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowscodecsext.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowscodecsext.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowsperformancerecordercontrol.dll,*:\Program Files\windows kits\10\windows performance toolkit*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecordercontrol.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecordercontrol.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,windowsperformancerecorderui.dll,*:\Program Files\Windows Kits\10\Windows Performance Toolkit*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,windowsudk.shellcommon.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,windowsudk.shellcommon.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winhttp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winhttp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wininet.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wininet.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winipsec.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winipsec.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmde.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmm.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winmm.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winnsi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winnsi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winrnr.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winrnr.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,winscard.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winscard.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winsqlite3.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsqlite3.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsta.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsta.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,winsync.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winsync.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,winutils.dll,*:\Program Files\Palo Alto Networks\Traps*,T1574.002,https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/ +TRUE,wkscli.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wkscli.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlanapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlanapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlancfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlancfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wldp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wldp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wlidprov.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wlidprov.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiclnt.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmiclnt.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmidcom.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmidcom.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiutils.dll,*:\Windows\System32\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmiutils.dll,*:\Windows\SysWOW64\wbem*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wmpdui.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmsgapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wmsgapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wofutil.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wofutil.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wpdshext.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wpdshext.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wsc.dll,*:\Program Files\AVAST Software\Avast*,T1574.001,https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2 +TRUE,wscapi.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wscapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wsdapi.dll,*:\Windows\System32\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,wsdapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ +TRUE,wshbth.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wshbth.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,wshelper.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wshelper.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wsmsvc.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wsmsvc.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,wtsapi32.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wtsapi32.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwancfg.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwancfg.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwapi.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,wwapi.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xmllite.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xmllite.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xolehlp.dll,*:\Windows\System32\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xolehlp.dll,*:\Windows\SysWOW64\*,T1574.002,https://wietze.github.io/blog/hijacking-dlls-in-windows +TRUE,xpsservices.dll,*:\Windows\System32\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,xpsservices.dll,*:\Windows\SysWOW64\*,T1574.002,https://securityintelligence.com/posts/windows-features-dll-sideloading/ +TRUE,xwizards.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwizards.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwtpw32.dll,*:\Windows\System32\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables +TRUE,xwtpw32.dll,*:\Windows\SysWOW64\*,T1574.007,https://wietze.github.io/blog/save-the-environment-variables diff --git a/lookups/csv/hijacklibs_loaded.yml b/lookups/csv/hijacklibs_loaded.yml index 425e4b75ac8..866fe9c35c4 100644 --- a/lookups/csv/hijacklibs_loaded.yml +++ b/lookups/csv/hijacklibs_loaded.yml @@ -1,8 +1,8 @@ name: hijacklibs_loaded id: 0a58a703-3a7a-4b27-a82b-f5a61acd3f1a -version: 5 +version: 4 creation_date: '2021-07-12' -modification_date: '2026-09-29' +modification_date: '2026-05-13' author: Splunk Threat Research Team lookup_type: csv description: A list of potentially abused libraries in Windows From b5d88399941f5b505f5e67023fd670f020fe1e2c Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 1 Oct 2026 11:22:28 +0200 Subject: [PATCH 08/10] Update windows_known_abused_dll_loaded_suspiciously.yml --- .../endpoint/windows_known_abused_dll_loaded_suspiciously.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 8e96e2cfc42..cdede1c4363 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -105,7 +105,7 @@ search: |- | lookup local=t hijacklibs_loaded library AS loaded_file OUTPUT islibrary comment as reference | lookup local=t hijacklibs_loaded library AS loaded_file excludes AS loaded_file_path OUTPUT islibrary AS excluded - | where islibrary="TRUE" AND isnull(excluded) + | where islibrary="TRUE" AND excluded="false" | stats count min(_time) as firstTime max(_time) as lastTime From 21fb1b31656b09582b7c201c50a56a1b1552df0a Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Fri, 2 Oct 2026 12:07:24 +0200 Subject: [PATCH 09/10] Update detections/endpoint/windows_defender_asr_audit_events.yml --- detections/endpoint/windows_defender_asr_audit_events.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_defender_asr_audit_events.yml b/detections/endpoint/windows_defender_asr_audit_events.yml index 879e96cd554..ad273795234 100644 --- a/detections/endpoint/windows_defender_asr_audit_events.yml +++ b/detections/endpoint/windows_defender_asr_audit_events.yml @@ -21,7 +21,7 @@ search: |- 1132, 1134 ) - | fillnull + | fillnull value=NULL | stats count min(_time) as firstTime max(_time) as lastTime by host EventCode From ca15a55487c386a06eff77a75d35510056c92652 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Fri, 2 Oct 2026 12:07:31 +0200 Subject: [PATCH 10/10] Update detections/endpoint/windows_defender_asr_block_events.yml --- detections/endpoint/windows_defender_asr_block_events.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_defender_asr_block_events.yml b/detections/endpoint/windows_defender_asr_block_events.yml index ef0f87e9a69..6d02f418c06 100644 --- a/detections/endpoint/windows_defender_asr_block_events.yml +++ b/detections/endpoint/windows_defender_asr_block_events.yml @@ -24,7 +24,7 @@ search: |- 1131, 1133 ) - | fillnull + | fillnull value=NULL | stats count min(_time) as firstTime max(_time) as lastTime by host EventCode