Title:Registry Modification for OCI DLL Redirection Status:experimental Description:Detects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings.
Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.
References: -https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/ Author: Swachchhanda Shrawan Poudel (Nextron Systems) Date: 2026-01-24 modified:None Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.execution'
-'attack.stealth'
-'attack.defense-impairment'
-'attack.t1112'
-'attack.t1574.001'
Logsource:
category: registry_set
product: windows
Detection: selection_ocilib: TargetObject|endswith:
'\SOFTWARE\Microsoft\MSDTC\MTxOCI\OracleOciLib' filter_main_ocilib_file: Details|contains:
'oci.dll' selection_ocilibpath: TargetObject|endswith:
'\SOFTWARE\Microsoft\MSDTC\MTxOCI\OracleOciLibPath' filter_main_ocilibpath: Details|contains:
'%SystemRoot%\System32\' condition:(selection_ocilib and not filter_main_ocilib_file) or (selection_ocilibpath and not filter_main_ocilibpath) Falsepositives:
-Unlikely Level:high