This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential DLL Sideloading Of DbgModel.DLL
Original Source:
[Sigma source]
Title:
Potential DLL Sideloading Of DbgModel.DLL
Status:
test
Description:
Detects potential DLL sideloading of "DbgModel.dll"
References:
-https://hijacklibs.net/entries/microsoft/built-in/dbgmodel.html
Author:
Gary Lobermier
Date:
2024-07-11
modified:
2024-07-22
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
product: windows
category: image_load
Detection:
selection:
ImageLoaded|endswith
:
'\dbgmodel.dll'
filter_main_generic:
ImageLoaded|startswith
:
-'C:\Windows\System32\'
-'C:\Windows\SysWOW64\'
-'C:\Windows\WinSxS\'
filter_optional_windbg:
ImageLoaded|startswith
:
'C:\Program Files\WindowsApps\Microsoft.WinDbg_'
filter_optional_windows_kits:
ImageLoaded|startswith
:
-'C:\Program Files (x86)\Windows Kits\'
-'C:\Program Files\Windows Kits\'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Legitimate applications loading their own versions of the DLL mentioned in this rule
Level:
medium