{"id":"75edd3fd-7146-48e5-9848-3013d7f0282c","title":"DHCP Server Error Failed Loading the CallOut DLL","description":"This rule detects a DHCP server error in which a specified Callout DLL (in registry) could not be loaded","author":"Dimitrios Slamaris, @atc_project (fix)","status":"test","level":"high","date":"2017-05-15","modified":"2022-12-25","tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.001"],"technique_ids":["T1574.001"],"logsource":{"product":"windows","service":"system"},"falsepositives":["Unknown"],"references":["https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html","https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx","https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx"],"source_path":"rules/windows/builtin/system/microsoft_windows_dhcp_server/win_system_susp_dhcp_config_failed.yml","source_sha256":"76ad6f537c54f771ce61cfa2d8b04d9ae0b30dc79d7c1b1461542f33e1272b16","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/microsoft_windows_dhcp_server/win_system_susp_dhcp_config_failed.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: DHCP Server Error Failed Loading the CallOut DLL\nid: 75edd3fd-7146-48e5-9848-3013d7f0282c\nstatus: test\ndescription: This rule detects a DHCP server error in which a specified Callout DLL (in registry) could not be loaded\nreferences:\n    - https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html\n    - https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx\n    - https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx\nauthor: 'Dimitrios Slamaris, @atc_project (fix)'\ndate: 2017-05-15\nmodified: 2022-12-25\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.execution\n    - attack.stealth\n    - attack.t1574.001\nlogsource:\n    product: windows\n    service: system\ndetection:\n    selection:\n        EventID:\n            - 1031\n            - 1032\n            - 1034\n        Provider_Name: Microsoft-Windows-DHCP-Server\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1574.001","id":"T1574.001","name":"DLL","page":"techniques/enterprise/T1574.001/"}],"data_path":"data/detection-rules/75edd3fd-7146-48e5-9848-3013d7f0282c.json","kind":"sigma"}
