Registry Modification for OCI DLL Redirection

 Original Source: [Sigma source]
Title: Registry Modification for OCI DLL Redirection
Status: experimental
Description:Detects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings. Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.
References:
  -https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2026-01-24
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1112'
  • -'attack.t1574.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_ocilib:
    TargetObject|endswith: '\SOFTWARE\Microsoft\MSDTC\MTxOCI\OracleOciLib'
  filter_main_ocilib_file:
    Details|contains: 'oci.dll'
  selection_ocilibpath:
    TargetObject|endswith: '\SOFTWARE\Microsoft\MSDTC\MTxOCI\OracleOciLibPath'
  filter_main_ocilibpath:
    Details|contains: '%SystemRoot%\System32\'
  condition:(selection_ocilib and not filter_main_ocilib_file) or (selection_ocilibpath and not filter_main_ocilibpath)
Falsepositives:
  -Unlikely
Level: high