Detection rules › Sigma
Potential System DLL Sideloading From Non System Locations
Detects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.).
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence | T1574.001 Hijack Execution Flow: DLL |
| Privilege Escalation | T1574.001 Hijack Execution Flow: DLL |
| Defense Evasion | T1574.001 Hijack Execution Flow: DLL |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Sysmon | 7 | Image loaded |
Stages and Predicates
Stage 1: selection
or:
ImageLoaded|endswith: '\COMRES.DLL'
ImageLoaded|endswith: '\DispBroker.dll'
ImageLoaded|endswith: '\FXSRESM.DLL'
ImageLoaded|endswith: '\FxsCompose.dll'
ImageLoaded|endswith: '\PrintIsolationProxy.dll'
ImageLoaded|endswith: '\TSMSISrv.dll'
ImageLoaded|endswith: '\TSVIPSrv.dll'
ImageLoaded|endswith: '\WLBSCTRL.dll'
ImageLoaded|endswith: '\WfsR.dll'
ImageLoaded|endswith: '\WptsExtensions.dll'
ImageLoaded|endswith: '\aclui.dll'
ImageLoaded|endswith: '\activeds.dll'
ImageLoaded|endswith: '\adsldpc.dll'
ImageLoaded|endswith: '\aepic.dll'
ImageLoaded|endswith: '\amsi.dll'
ImageLoaded|endswith: '\apphelp.dll'
ImageLoaded|endswith: '\applicationframe.dll'
ImageLoaded|endswith: '\appraiser.dll'
ImageLoaded|endswith: '\appvpolicy.dll'
ImageLoaded|endswith: '\appxalluserstore.dll'
ImageLoaded|endswith: '\appxdeploymentclient.dll'
ImageLoaded|endswith: '\archiveint.dll'
ImageLoaded|endswith: '\atl.dll'
ImageLoaded|endswith: '\audioses.dll'
ImageLoaded|endswith: '\auditpolcore.dll'
ImageLoaded|endswith: '\authfwcfg.dll'
ImageLoaded|endswith: '\authz.dll'
ImageLoaded|endswith: '\avrt.dll'
ImageLoaded|endswith: '\batmeter.dll'
ImageLoaded|endswith: '\bcd.dll'
ImageLoaded|endswith: '\bcp47langs.dll'
ImageLoaded|endswith: '\bcp47mrm.dll'
ImageLoaded|endswith: '\bcrypt.dll'
ImageLoaded|endswith: '\bderepair.dll'
ImageLoaded|endswith: '\bootmenuux.dll'
ImageLoaded|endswith: '\bootux.dll'
ImageLoaded|endswith: '\cabinet.dll'
ImageLoaded|endswith: '\cabview.dll'
ImageLoaded|endswith: '\certcli.dll'
ImageLoaded|endswith: '\certenroll.dll'
ImageLoaded|endswith: '\cfgmgr32.dll'
ImageLoaded|endswith: '\cldapi.dll'
ImageLoaded|endswith: '\clipc.dll'
ImageLoaded|endswith: '\clusapi.dll'
ImageLoaded|endswith: '\cmpbk32.dll'
ImageLoaded|endswith: '\cmutil.dll'
ImageLoaded|endswith: '\coloradapterclient.dll'
ImageLoaded|endswith: '\colorui.dll'
ImageLoaded|endswith: '\comdlg32.dll'
ImageLoaded|endswith: '\configmanager2.dll'
ImageLoaded|endswith: '\connect.dll'
ImageLoaded|endswith: '\coredplus.dll'
ImageLoaded|endswith: '\coremessaging.dll'
ImageLoaded|endswith: '\coreuicomponents.dll'
ImageLoaded|endswith: '\credui.dll'
ImageLoaded|endswith: '\cryptbase.dll'
ImageLoaded|endswith: '\cryptdll.dll'
ImageLoaded|endswith: '\cryptnet.dll'
ImageLoaded|endswith: '\cryptsp.dll'
ImageLoaded|endswith: '\cryptui.dll'
ImageLoaded|endswith: '\cryptxml.dll'
ImageLoaded|endswith: '\cscapi.dll'
ImageLoaded|endswith: '\cscobj.dll'
ImageLoaded|endswith: '\cscui.dll'
ImageLoaded|endswith: '\d2d1.dll'
ImageLoaded|endswith: '\d3d10.dll'
ImageLoaded|endswith: '\d3d10_1.dll'
ImageLoaded|endswith: '\d3d10_1core.dll'
ImageLoaded|endswith: '\d3d10core.dll'
ImageLoaded|endswith: '\d3d10warp.dll'
ImageLoaded|endswith: '\d3d11.dll'
ImageLoaded|endswith: '\d3d12.dll'
ImageLoaded|endswith: '\d3d9.dll'
ImageLoaded|endswith: '\d3dx9_43.dll'
ImageLoaded|endswith: '\dataexchange.dll'
ImageLoaded|endswith: '\davclnt.dll'
ImageLoaded|endswith: '\dcntel.dll'
ImageLoaded|endswith: '\dcomp.dll'
ImageLoaded|endswith: '\defragproxy.dll'
ImageLoaded|endswith: '\desktopshellext.dll'
ImageLoaded|endswith: '\deviceassociation.dll'
ImageLoaded|endswith: '\devicecredential.dll'
ImageLoaded|endswith: '\devicepairing.dll'
ImageLoaded|endswith: '\devobj.dll'
ImageLoaded|endswith: '\devrtl.dll'
ImageLoaded|endswith: '\dhcpcmonitor.dll'
ImageLoaded|endswith: '\dhcpcsvc.dll'
ImageLoaded|endswith: '\dhcpcsvc6.dll'
ImageLoaded|endswith: '\directmanipulation.dll'
ImageLoaded|endswith: '\dismapi.dll'
ImageLoaded|endswith: '\dismcore.dll'
ImageLoaded|endswith: '\dmcfgutils.dll'
ImageLoaded|endswith: '\dmcmnutils.dll'
ImageLoaded|endswith: '\dmcommandlineutils.dll'
ImageLoaded|endswith: '\dmenrollengine.dll'
ImageLoaded|endswith: '\dmenterprisediagnostics.dll'
ImageLoaded|endswith: '\dmiso8601utils.dll'
ImageLoaded|endswith: '\dmoleaututils.dll'
ImageLoaded|endswith: '\dmprocessxmlfiltered.dll'
ImageLoaded|endswith: '\dmpushproxy.dll'
ImageLoaded|endswith: '\dmxmlhelputils.dll'
ImageLoaded|endswith: '\dnsapi.dll'
ImageLoaded|endswith: '\dot3api.dll'
ImageLoaded|endswith: '\dot3cfg.dll'
ImageLoaded|endswith: '\dpx.dll'
ImageLoaded|endswith: '\drprov.dll'
ImageLoaded|endswith: '\drvstore.dll'
ImageLoaded|endswith: '\dsclient.dll'
ImageLoaded|endswith: '\dsound.dll'
ImageLoaded|endswith: '\dsparse.dll'
ImageLoaded|endswith: '\dsprop.dll'
ImageLoaded|endswith: '\dsreg.dll'
ImageLoaded|endswith: '\dsrole.dll'
ImageLoaded|endswith: '\dui70.dll'
ImageLoaded|endswith: '\duser.dll'
ImageLoaded|endswith: '\dusmapi.dll'
ImageLoaded|endswith: '\dwmapi.dll'
ImageLoaded|endswith: '\dwmcore.dll'
ImageLoaded|endswith: '\dwrite.dll'
ImageLoaded|endswith: '\dxcore.dll'
ImageLoaded|endswith: '\dxgi.dll'
ImageLoaded|endswith: '\dxilconv.dll'
ImageLoaded|endswith: '\dxva2.dll'
ImageLoaded|endswith: '\dynamoapi.dll'
ImageLoaded|endswith: '\eappcfg.dll'
ImageLoaded|endswith: '\eappprxy.dll'
ImageLoaded|endswith: '\edgeiso.dll'
ImageLoaded|endswith: '\edputil.dll'
ImageLoaded|endswith: '\efsadu.dll'
ImageLoaded|endswith: '\efsutil.dll'
ImageLoaded|endswith: '\esent.dll'
ImageLoaded|endswith: '\execmodelproxy.dll'
ImageLoaded|endswith: '\explorerframe.dll'
ImageLoaded|endswith: '\fastprox.dll'
ImageLoaded|endswith: '\faultrep.dll'
ImageLoaded|endswith: '\fddevquery.dll'
ImageLoaded|endswith: '\feclient.dll'
ImageLoaded|endswith: '\fhcfg.dll'
ImageLoaded|endswith: '\fhsvcctl.dll'
ImageLoaded|endswith: '\firewallapi.dll'
ImageLoaded|endswith: '\flightsettings.dll'
ImageLoaded|endswith: '\fltlib.dll'
ImageLoaded|endswith: '\framedynos.dll'
ImageLoaded|endswith: '\fveapi.dll'
ImageLoaded|endswith: '\fveskybackup.dll'
ImageLoaded|endswith: '\fvewiz.dll'
ImageLoaded|endswith: '\fwbase.dll'
ImageLoaded|endswith: '\fwcfg.dll'
ImageLoaded|endswith: '\fwpolicyiomgr.dll'
ImageLoaded|endswith: '\fwpuclnt.dll'
ImageLoaded|endswith: '\fxsapi.dll'
ImageLoaded|endswith: '\fxsst.dll'
ImageLoaded|endswith: '\fxstiff.dll'
ImageLoaded|endswith: '\getuname.dll'
ImageLoaded|endswith: '\gpapi.dll'
ImageLoaded|endswith: '\hid.dll'
ImageLoaded|endswith: '\hnetmon.dll'
ImageLoaded|endswith: '\httpapi.dll'
ImageLoaded|endswith: '\icmp.dll'
ImageLoaded|endswith: '\idstore.dll'
ImageLoaded|endswith: '\ieadvpack.dll'
ImageLoaded|endswith: '\iedkcs32.dll'
ImageLoaded|endswith: '\iernonce.dll'
ImageLoaded|endswith: '\iertutil.dll'
ImageLoaded|endswith: '\ifmon.dll'
ImageLoaded|endswith: '\ifsutil.dll'
ImageLoaded|endswith: '\igd10iumd64.dll'
ImageLoaded|endswith: '\igd12umd64.dll'
ImageLoaded|endswith: '\igdumdim64.dll'
ImageLoaded|endswith: '\igdusc64.dll'
ImageLoaded|endswith: '\inproclogger.dll'
ImageLoaded|endswith: '\iphlpapi.dll'
ImageLoaded|endswith: '\iri.dll'
ImageLoaded|endswith: '\iscsidsc.dll'
ImageLoaded|endswith: '\iscsium.dll'
ImageLoaded|endswith: '\isv.exe_rsaenh.dll'
ImageLoaded|endswith: '\iumbase.dll'
ImageLoaded|endswith: '\iumsdk.dll'
ImageLoaded|endswith: '\joinutil.dll'
ImageLoaded|endswith: '\kdstub.dll'
ImageLoaded|endswith: '\ksuser.dll'
ImageLoaded|endswith: '\ktmw32.dll'
ImageLoaded|endswith: '\licensemanagerapi.dll'
ImageLoaded|endswith: '\licensingdiagspp.dll'
ImageLoaded|endswith: '\linkinfo.dll'
ImageLoaded|endswith: '\loadperf.dll'
ImageLoaded|endswith: '\lockhostingframework.dll'
ImageLoaded|endswith: '\logoncli.dll'
ImageLoaded|endswith: '\logoncontroller.dll'
ImageLoaded|endswith: '\lpksetupproxyserv.dll'
ImageLoaded|endswith: '\lrwizdll.dll'
ImageLoaded|endswith: '\magnification.dll'
ImageLoaded|endswith: '\maintenanceui.dll'
ImageLoaded|endswith: '\mapistub.dll'
ImageLoaded|endswith: '\mbaexmlparser.dll'
ImageLoaded|endswith: '\mdmdiagnostics.dll'
ImageLoaded|endswith: '\mfc42u.dll'
ImageLoaded|endswith: '\mfcore.dll'
ImageLoaded|endswith: '\mfplat.dll'
ImageLoaded|endswith: '\mi.dll'
ImageLoaded|endswith: '\midimap.dll'
ImageLoaded|endswith: '\mintdh.dll'
ImageLoaded|endswith: '\miutils.dll'
ImageLoaded|endswith: '\mlang.dll'
ImageLoaded|endswith: '\mmdevapi.dll'
ImageLoaded|endswith: '\mobilenetworking.dll'
ImageLoaded|endswith: '\mpr.dll'
ImageLoaded|endswith: '\mprapi.dll'
ImageLoaded|endswith: '\mrmcorer.dll'
ImageLoaded|endswith: '\msacm32.dll'
ImageLoaded|endswith: '\mscms.dll'
ImageLoaded|endswith: '\mscoree.dll'
ImageLoaded|endswith: '\msctf.dll'
ImageLoaded|endswith: '\msctfmonitor.dll'
ImageLoaded|endswith: '\msdrm.dll'
ImageLoaded|endswith: '\msdtcVSp1res.dll'
ImageLoaded|endswith: '\msdtctm.dll'
ImageLoaded|endswith: '\msftedit.dll'
ImageLoaded|endswith: '\msi.dll'
ImageLoaded|endswith: '\msiso.dll'
ImageLoaded|endswith: '\msutb.dll'
ImageLoaded|endswith: '\msvcp110_win.dll'
ImageLoaded|endswith: '\mswb7.dll'
ImageLoaded|endswith: '\mswsock.dll'
ImageLoaded|endswith: '\msxml3.dll'
ImageLoaded|endswith: '\mtxclu.dll'
ImageLoaded|endswith: '\napinsp.dll'
ImageLoaded|endswith: '\ncrypt.dll'
ImageLoaded|endswith: '\ndfapi.dll'
ImageLoaded|endswith: '\netapi32.dll'
ImageLoaded|endswith: '\netid.dll'
ImageLoaded|endswith: '\netiohlp.dll'
ImageLoaded|endswith: '\netjoin.dll'
ImageLoaded|endswith: '\netplwiz.dll'
ImageLoaded|endswith: '\netprofm.dll'
ImageLoaded|endswith: '\netprovfw.dll'
ImageLoaded|endswith: '\netsetupapi.dll'
ImageLoaded|endswith: '\netshell.dll'
ImageLoaded|endswith: '\nettrace.dll'
ImageLoaded|endswith: '\netutils.dll'
ImageLoaded|endswith: '\networkexplorer.dll'
ImageLoaded|endswith: '\newdev.dll'
ImageLoaded|endswith: '\ninput.dll'
ImageLoaded|endswith: '\nlaapi.dll'
ImageLoaded|endswith: '\nlansp_c.dll'
ImageLoaded|endswith: '\npmproxy.dll'
ImageLoaded|endswith: '\nshhttp.dll'
ImageLoaded|endswith: '\nshipsec.dll'
ImageLoaded|endswith: '\nshwfp.dll'
ImageLoaded|endswith: '\ntdsapi.dll'
ImageLoaded|endswith: '\ntlanman.dll'
ImageLoaded|endswith: '\ntlmshared.dll'
ImageLoaded|endswith: '\ntmarta.dll'
ImageLoaded|endswith: '\ntshrui.dll'
ImageLoaded|endswith: '\oleacc.dll'
ImageLoaded|endswith: '\omadmapi.dll'
ImageLoaded|endswith: '\onex.dll'
ImageLoaded|endswith: '\opcservices.dll'
ImageLoaded|endswith: '\osbaseln.dll'
ImageLoaded|endswith: '\osksupport.dll'
ImageLoaded|endswith: '\osuninst.dll'
ImageLoaded|endswith: '\p2p.dll'
ImageLoaded|endswith: '\p2pnetsh.dll'
ImageLoaded|endswith: '\p9np.dll'
ImageLoaded|endswith: '\pcaui.dll'
ImageLoaded|endswith: '\pdh.dll'
ImageLoaded|endswith: '\peerdistsh.dll'
ImageLoaded|endswith: '\pkeyhelper.dll'
ImageLoaded|endswith: '\pla.dll'
ImageLoaded|endswith: '\playsndsrv.dll'
ImageLoaded|endswith: '\pnrpnsp.dll'
ImageLoaded|endswith: '\policymanager.dll'
ImageLoaded|endswith: '\polstore.dll'
ImageLoaded|endswith: '\powrprof.dll'
ImageLoaded|endswith: '\printui.dll'
ImageLoaded|endswith: '\prntvpt.dll'
ImageLoaded|endswith: '\profapi.dll'
ImageLoaded|endswith: '\propsys.dll'
ImageLoaded|endswith: '\proximitycommon.dll'
ImageLoaded|endswith: '\proximityservicepal.dll'
ImageLoaded|endswith: '\prvdmofcomp.dll'
ImageLoaded|endswith: '\puiapi.dll'
ImageLoaded|endswith: '\radcui.dll'
ImageLoaded|endswith: '\rasapi32.dll'
ImageLoaded|endswith: '\rasdlg.dll'
ImageLoaded|endswith: '\rasgcw.dll'
ImageLoaded|endswith: '\rasman.dll'
ImageLoaded|endswith: '\rasmontr.dll'
ImageLoaded|endswith: '\rdpendp.dll'
ImageLoaded|endswith: '\reagent.dll'
ImageLoaded|endswith: '\regapi.dll'
ImageLoaded|endswith: '\reseteng.dll'
ImageLoaded|endswith: '\resetengine.dll'
ImageLoaded|endswith: '\resutils.dll'
ImageLoaded|endswith: '\rmclient.dll'
ImageLoaded|endswith: '\rpchttp.dll'
ImageLoaded|endswith: '\rpcnsh.dll'
ImageLoaded|endswith: '\rsaenh.dll'
ImageLoaded|endswith: '\rtutils.dll'
ImageLoaded|endswith: '\rtworkq.dll'
ImageLoaded|endswith: '\samcli.dll'
ImageLoaded|endswith: '\samlib.dll'
ImageLoaded|endswith: '\sapi_onecore.dll'
ImageLoaded|endswith: '\sas.dll'
ImageLoaded|endswith: '\scansetting.dll'
ImageLoaded|endswith: '\scecli.dll'
ImageLoaded|endswith: '\schedcli.dll'
ImageLoaded|endswith: '\secur32.dll'
ImageLoaded|endswith: '\security.dll'
ImageLoaded|endswith: '\sensapi.dll'
ImageLoaded|endswith: '\shell32.dll'
ImageLoaded|endswith: '\shfolder.dll'
ImageLoaded|endswith: '\slc.dll'
ImageLoaded|endswith: '\snmpapi.dll'
ImageLoaded|endswith: '\spectrumsyncclient.dll'
ImageLoaded|endswith: '\spp.dll'
ImageLoaded|endswith: '\sppc.dll'
ImageLoaded|endswith: '\sppcext.dll'
ImageLoaded|endswith: '\srclient.dll'
ImageLoaded|endswith: '\srcore.dll'
ImageLoaded|endswith: '\srmtrace.dll'
ImageLoaded|endswith: '\srpapi.dll'
ImageLoaded|endswith: '\srvcli.dll'
ImageLoaded|endswith: '\ssp.exe_rsaenh.dll'
ImageLoaded|endswith: '\ssp_isv.exe_rsaenh.dll'
ImageLoaded|endswith: '\sspicli.dll'
ImageLoaded|endswith: '\ssshim.dll'
ImageLoaded|endswith: '\staterepository.core.dll'
ImageLoaded|endswith: '\storageusage.dll'
ImageLoaded|endswith: '\structuredquery.dll'
ImageLoaded|endswith: '\sxshared.dll'
ImageLoaded|endswith: '\systemsettingsthresholdadminflowui.dll'
ImageLoaded|endswith: '\tapi32.dll'
ImageLoaded|endswith: '\tbs.dll'
ImageLoaded|endswith: '\tdh.dll'
ImageLoaded|endswith: '\textshaping.dll'
ImageLoaded|endswith: '\timesync.dll'
ImageLoaded|endswith: '\tpmcoreprovisioning.dll'
ImageLoaded|endswith: '\tquery.dll'
ImageLoaded|endswith: '\tsworkspace.dll'
ImageLoaded|endswith: '\ttdrecord.dll'
ImageLoaded|endswith: '\twext.dll'
ImageLoaded|endswith: '\twinapi.dll'
ImageLoaded|endswith: '\twinui.appcore.dll'
ImageLoaded|endswith: '\uianimation.dll'
ImageLoaded|endswith: '\uiautomationcore.dll'
ImageLoaded|endswith: '\uireng.dll'
ImageLoaded|endswith: '\uiribbon.dll'
ImageLoaded|endswith: '\umpdc.dll'
ImageLoaded|endswith: '\unattend.dll'
ImageLoaded|endswith: '\updatepolicy.dll'
ImageLoaded|endswith: '\upshared.dll'
ImageLoaded|endswith: '\urlmon.dll'
ImageLoaded|endswith: '\userenv.dll'
ImageLoaded|endswith: '\utcutil.dll'
ImageLoaded|endswith: '\utildll.dll'
ImageLoaded|endswith: '\uxinit.dll'
ImageLoaded|endswith: '\uxtheme.dll'
ImageLoaded|endswith: '\vaultcli.dll'
ImageLoaded|endswith: '\vdsutil.dll'
ImageLoaded|endswith: '\version.dll'
ImageLoaded|endswith: '\virtdisk.dll'
ImageLoaded|endswith: '\vssapi.dll'
ImageLoaded|endswith: '\vsstrace.dll'
ImageLoaded|endswith: '\wbemcomn.dll'
ImageLoaded|endswith: '\wbemprox.dll'
ImageLoaded|endswith: '\wbemsvc.dll'
ImageLoaded|endswith: '\wcmapi.dll'
ImageLoaded|endswith: '\wcnnetsh.dll'
ImageLoaded|endswith: '\wdi.dll'
ImageLoaded|endswith: '\wdscore.dll'
ImageLoaded|endswith: '\webservices.dll'
ImageLoaded|endswith: '\wecapi.dll'
ImageLoaded|endswith: '\wer.dll'
ImageLoaded|endswith: '\wevtapi.dll'
ImageLoaded|endswith: '\whhelper.dll'
ImageLoaded|endswith: '\wimgapi.dll'
ImageLoaded|endswith: '\winbio.dll'
ImageLoaded|endswith: '\winbrand.dll'
ImageLoaded|endswith: '\windows.storage.dll'
ImageLoaded|endswith: '\windows.storage.search.dll'
ImageLoaded|endswith: '\windows.ui.immersive.dll'
ImageLoaded|endswith: '\windowscodecs.dll'
ImageLoaded|endswith: '\windowscodecsext.dll'
ImageLoaded|endswith: '\windowsudk.shellcommon.dll'
ImageLoaded|endswith: '\winhttp.dll'
ImageLoaded|endswith: '\wininet.dll'
ImageLoaded|endswith: '\winipsec.dll'
ImageLoaded|endswith: '\winmde.dll'
ImageLoaded|endswith: '\winmm.dll'
ImageLoaded|endswith: '\winnsi.dll'
ImageLoaded|endswith: '\winrnr.dll'
ImageLoaded|endswith: '\winscard.dll'
ImageLoaded|endswith: '\winsqlite3.dll'
ImageLoaded|endswith: '\winsta.dll'
ImageLoaded|endswith: '\winsync.dll'
ImageLoaded|endswith: '\wkscli.dll'
ImageLoaded|endswith: '\wlanapi.dll'
ImageLoaded|endswith: '\wlancfg.dll'
ImageLoaded|endswith: '\wldp.dll'
ImageLoaded|endswith: '\wlidprov.dll'
ImageLoaded|endswith: '\wmiclnt.dll'
ImageLoaded|endswith: '\wmidcom.dll'
ImageLoaded|endswith: '\wmiutils.dll'
ImageLoaded|endswith: '\wmpdui.dll'
ImageLoaded|endswith: '\wmsgapi.dll'
ImageLoaded|endswith: '\wofutil.dll'
ImageLoaded|endswith: '\wow64log.dll'
ImageLoaded|endswith: '\wpdshext.dll'
ImageLoaded|endswith: '\wscapi.dll'
ImageLoaded|endswith: '\wsdapi.dll'
ImageLoaded|endswith: '\wshbth.dll'
ImageLoaded|endswith: '\wshelper.dll'
ImageLoaded|endswith: '\wsmsvc.dll'
ImageLoaded|endswith: '\wtsapi32.dll'
ImageLoaded|endswith: '\wwancfg.dll'
ImageLoaded|endswith: '\wwapi.dll'
ImageLoaded|endswith: '\xmllite.dll'
ImageLoaded|endswith: '\xolehlp.dll'
ImageLoaded|endswith: '\xpsservices.dll'
ImageLoaded|endswith: '\xwizards.dll'
ImageLoaded|endswith: '\xwtpw32.dll'
Stage 2: not 1 of filter_main_*
or:
or:
Image|endswith: '\TiWorker.exe'
Image|endswith: '\wuaucltcore.exe'
or:
Image|startswith: 'C:\Windows\UUS\arm64\'
Image|startswith: 'C:\Windows\WinSxS\arm64'
ImageLoaded|startswith: 'C:\Windows\Temp\'
ImageLoaded|endswith: '\cscui.dll'
ImageLoaded|startswith: 'C:\Windows\Microsoft.NET\'
ImageLoaded|endswith: '\d3dx9_43.dll'
ImageLoaded|startswith: 'C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_'
ImageLoaded|endswith: '\version.dll'
ImageLoaded|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
ImageLoaded|contains: 'C:\$WINDOWS.~BT\'
ImageLoaded|contains: 'C:\$WinREAgent\'
ImageLoaded|contains: 'C:\Windows\SoftwareDistribution\'
ImageLoaded|contains: 'C:\Windows\SyChpe32\'
ImageLoaded|contains: 'C:\Windows\SysWOW64\'
ImageLoaded|contains: 'C:\Windows\System32\'
ImageLoaded|contains: 'C:\Windows\SystemTemp\'
ImageLoaded|contains: 'C:\Windows\WinSxS\'
Stage 3: not 1 of filter_optional_*
or:
or:
Image|contains: 'C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs'
Image|contains: 'C:\Windows\System32\backgroundTaskHost.exe'
ImageLoaded|startswith: 'C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs'
or:
Image|startswith: 'C:\Program Files (x86)\CheckPoint\'
Image|startswith: 'C:\Program Files\CheckPoint\'
or:
ImageLoaded|startswith: 'C:\Program Files (x86)\CheckPoint\'
ImageLoaded|startswith: 'C:\Program Files\CheckPoint\'
Image|endswith: '\SmartConsole.exe'
ImageLoaded|endswith: '\PolicyManager.dll'
or:
ImageLoaded|endswith: '\mi.dll'
ImageLoaded|endswith: '\miutils.dl'
ImageLoaded|startswith: 'C:\Program Files\Arsenal-Image-Mounter-'
Image|endswith: '\wldp.dll'
Image|startswith: 'C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs'
Image: 'C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe'
ImageLoaded: 'C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll'
ImageLoaded|endswith: '\mswb7.dll'
ImageLoaded|startswith: 'C:\Program Files\Microsoft\Exchange Server\'
ImageLoaded|startswith: 'C:\Packages\Plugins\Microsoft.GuestConfiguration.ConfigurationforWindows\'
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|---|---|
Image | ends_with |
|
Image | eq |
|
Image | match |
|
Image | starts_with |
|
ImageLoaded | ends_with |
|
ImageLoaded | eq |
|
ImageLoaded | match |
|
ImageLoaded | starts_with |
|