DHCP Server Loaded the CallOut DLL

 Original Source: [Sigma source]
Title: DHCP Server Loaded the CallOut DLL
Status: test
Description:This rule detects a DHCP server in which a specified Callout DLL (in registry) was loaded
References:
  -https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html
  -https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx
  -https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx
Author: Dimitrios Slamaris
Date: 2017-05-15
modified:2022-12-25
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    EventID: '1033'
    Provider_Name: 'Microsoft-Windows-DHCP-Server'
  condition:selection
Falsepositives:
  -Unknown
Level: high