New DLL Added to AppInit_DLLs Registry Key

 Original Source: [Sigma source]
Title: New DLL Added to AppInit_DLLs Registry Key
Status: test
Description:DLLs that are specified in the AppInit_DLLs value in the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows are loaded by user32.dll into every process that loads user32.dll
References:
  -https://eqllib.readthedocs.io/en/latest/analytics/822dc4c5-b355-4df8-bd37-29c458997b8f.html
Author: Ilyas Ochkov, oscd.community, Tim Shelton
Date: 2019-10-25
modified:2022-12-25
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.010'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    - TargetObject|endswith:
      - '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls'
      - '\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls'
    - NewName|endswith:
      - '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls'
      - '\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls'
  filter:
    Details: '(Empty)'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: medium