This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
DLL Sideloading Of ShellChromeAPI.DLL
Original Source:
[Sigma source]
Title:
DLL Sideloading Of ShellChromeAPI.DLL
Status:
test
Description:
Detects processes loading the non-existent DLL "ShellChromeAPI". One known example is the "DeviceEnroller" binary in combination with the "PhoneDeepLink" flag tries to load this DLL. Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
References:
-https://mobile.twitter.com/0gtweet/status/1564131230941122561
-https://strontic.github.io/xcyclopedia/library/DeviceEnroller.exe-24BEF0D6B0ECED36BB41831759FDE18D.html
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-12-01
modified:
None
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
category: image_load
product: windows
Detection:
selection:
ImageLoaded|endswith
:
'\ShellChromeAPI.dll'
condition
:
selection
Falsepositives:
-Unknown
Level:
high