{"id":"9d3436ef-9476-4c43-acca-90ce06bdf33a","title":"DHCP Callout DLL Installation","description":"Detects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)","author":"Dimitrios Slamaris","status":"test","level":"high","date":"2017-05-15","modified":"2023-08-17","tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.defense-impairment","attack.t1574.001","attack.t1112"],"technique_ids":["T1112","T1574.001"],"logsource":{"category":"registry_set","product":"windows"},"falsepositives":["Unknown"],"references":["https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html","https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx","https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx"],"source_path":"rules/windows/registry/registry_set/registry_set_dhcp_calloutdll.yml","source_sha256":"11f369f964efd9c5d2128ea12e27625d11d63b3fb115debe4c2cfe41888aca8a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_set/registry_set_dhcp_calloutdll.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: DHCP Callout DLL Installation\nid: 9d3436ef-9476-4c43-acca-90ce06bdf33a\nstatus: test\ndescription: Detects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)\nreferences:\n    - https://blog.3or.de/mimilib-dhcp-server-callout-dll-injection.html\n    - https://technet.microsoft.com/en-us/library/cc726884(v=ws.10).aspx\n    - https://msdn.microsoft.com/de-de/library/windows/desktop/aa363389(v=vs.85).aspx\nauthor: Dimitrios Slamaris\ndate: 2017-05-15\nmodified: 2023-08-17\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.execution\n    - attack.stealth\n    - attack.defense-impairment\n    - attack.t1574.001\n    - attack.t1112\nlogsource:\n    category: registry_set\n    product: windows\ndetection:\n    selection:\n        TargetObject|endswith:\n            - '\\Services\\DHCPServer\\Parameters\\CalloutDlls'\n            - '\\Services\\DHCPServer\\Parameters\\CalloutEnabled'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1112","id":"T1112","name":"Modify Registry","page":"techniques/enterprise/T1112/"},{"key":"enterprise/T1574.001","id":"T1574.001","name":"DLL","page":"techniques/enterprise/T1574.001/"}],"data_path":"data/detection-rules/9d3436ef-9476-4c43-acca-90ce06bdf33a.json","kind":"sigma"}
