New DLL Added to AppCertDlls Registry Key

 Original Source: [Sigma source]
Title: New DLL Added to AppCertDlls Registry Key
Status: test
Description:Dynamic-link libraries (DLLs) that are specified in the AppCertDLLs value in the Registry key can be abused to obtain persistence and privilege escalation by causing a malicious DLL to be loaded and run in the context of separate processes on the computer.
References:
  -http://www.hexacorn.com/blog/2013/01/19/beyond-good-ol-run-key-part-3/
  -https://eqllib.readthedocs.io/en/latest/analytics/14f90406-10a0-4d36-a672-31cabe149f2f.html
Author: Ilyas Ochkov, oscd.community
Date: 2019-10-25
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.009'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
TargetObject:'HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls' NewName:'HKLM\SYSTEM\CurentControlSet\Control\Session Manager\AppCertDlls'   condition:selection
Falsepositives:
  -Unknown
Level: medium