This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Initial Access via DLL Search Order Hijacking
Original Source:
[Sigma source]
Title:
Potential Initial Access via DLL Search Order Hijacking
Status:
test
Description:
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
References:
-https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d46dd4ac6866b4337ec126be8cee0e115467b3e8703794ba6f6df6432c806bc
-https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0
Author:
Tim Rauch (rule), Elastic (idea)
Date:
2022-10-21
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.execution'
-'attack.stealth'
-'attack.t1566'
-'attack.t1566.001'
-'attack.initial-access'
-'attack.t1574'
-'attack.t1574.001'
Logsource:
product: windows
category: file_event
Detection:
selection:
Image|endswith
:
-'\winword.exe'
-'\excel.exe'
-'\powerpnt.exe'
-'\MSACCESS.EXE'
-'\MSPUB.EXE'
-'\fltldr.exe'
-'\cmd.exe'
-'\certutil.exe'
-'\mshta.exe'
-'\cscript.exe'
-'\wscript.exe'
-'\curl.exe'
-'\powershell.exe'
-'\pwsh.exe'
TargetFilename|endswith
:
'.dll'
TargetFilename|contains|all
:
-'\Users\'
-'\AppData\'
TargetFilename|contains
:
-'\Microsoft\OneDrive\'
-'\Microsoft OneDrive\'
-'\Microsoft\Teams\'
-'\Local\slack\app-'
-'\Local\Programs\Microsoft VS Code\'
filter:
Image|endswith
:
'\cmd.exe'
TargetFilename|contains|all
:
-'\Users\'
-'\AppData\'
-'\Microsoft\OneDrive\'
-'\api-ms-win-core-'
condition
:
selection and not filter
Falsepositives:
-Unknown
Level:
medium