1200KM / detection
T1055.001 Dynamic-link Library Injection — Detection Rules
Detection workspace for T1055.001 Dynamic-link Library Injection: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- HackTool - Potential CobaltStrike Process Injection · test · high · {"product":"windows","category":"create_remote_thread"}
- ManageEngine Endpoint Central Dctask64.EXE Potential Abuse · test · high · {"category":"process_creation","product":"windows"}
- Mavinject Inject DLL Into Running Process · test · high · {"category":"process_creation","product":"windows"}
- Potential DLL Injection Or Execution Using Tracker.exe · test · medium · {"category":"process_creation","product":"windows"}
- Renamed ZOHO Dctask64 Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed Mavinject.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0389 Behavioral Detection of DLL Injection via Windows API
AN1095 Analytic 1095
Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.