1200KM / detection
T1574.001 DLL — Detection Rules
Detection workspace for T1574.001 DLL: 80 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Use Of Hidden Paths Or Files · test · low · {"product":"linux","service":"auditd"}
- DNS Server Error Failed Loading the ServerLevelPluginDLL · test · high · {"product":"windows","service":"dns-server"}
- Microsoft Defender Blocked from Loading Unsigned DLL · test · high · {"product":"windows","service":"security-mitigations"}
- Unsigned Binary Loaded From Suspicious Location · test · high · {"product":"windows","service":"security-mitigations"}
- DHCP Server Loaded the CallOut DLL · test · high · {"product":"windows","service":"system"}
- DHCP Server Error Failed Loading the CallOut DLL · test · high · {"product":"windows","service":"system"}
- Creation Of Non-Existent System DLL · test · medium · {"product":"windows","category":"file_event"}
- DLL Search Order Hijackig Via Additional Space in Path · test · high · {"category":"file_event","product":"windows"}
- HackTool - Powerup Write Hijack DLL · test · high · {"category":"file_event","product":"windows"}
- Potential Initial Access via DLL Search Order Hijacking · test · medium · {"product":"windows","category":"file_event"}
- Malicious DLL File Dropped in the Teams or OneDrive Folder · test · high · {"category":"file_event","product":"windows"}
- Creation of WerFault.exe/Wer.dll in Unusual Folder · test · medium · {"product":"windows","category":"file_event"}
- Potential Azure Browser SSO Abuse · test · low · {"category":"image_load","product":"windows"}
- Unsigned .node File Loaded · experimental · medium · {"category":"image_load","product":"windows"}
- Potential 7za.DLL Sideloading · test · low · {"category":"image_load","product":"windows"}
- Potential Antivirus Software DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential appverifUI.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Aruba Network Service Potential DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential AVKkid.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential CCleanerDU.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential CCleanerReactivator.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential Chrome Frame Helper DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Via ClassicExplorer32.dll · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Via comctl32.dll · test · high · {"category":"image_load","product":"windows"}
- System Control Panel Item Loaded From Uncommon Location · test · high · {"product":"windows","category":"image_load"}
- Potential DLL Sideloading Of DBGCORE.DLL · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Of DBGHELP.DLL · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Of DbgModel.DLL · test · medium · {"product":"windows","category":"image_load"}
- Potential EACore.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential Edputil.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential System DLL Sideloading From Non System Locations · test · high · {"category":"image_load","product":"windows"}
- Potential Goopdate.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE · test · medium · {"category":"image_load","product":"windows"}
- Potential Iviewers.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential JLI.dll Side-Loading · experimental · high · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Via JsSchHlp · test · medium · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE · test · high · {"category":"image_load","product":"windows"}
- Potential Libvlc.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential Mfdetours.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Unsigned Mfdetours.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Of MpSvc.DLL · test · medium · {"product":"windows","category":"image_load"}
- Potential DLL Sideloading Of MsCorSvc.DLL · test · medium · {"product":"windows","category":"image_load"}
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders · test · high · {"category":"image_load","product":"windows"}
- Microsoft Office DLL Sideload · test · high · {"category":"image_load","product":"windows"}
- Potential Python DLL SideLoading · test · medium · {"category":"image_load","product":"windows"}
- Potential Rcdll.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential RjvPlatform.DLL Sideloading From Default Location · test · medium · {"category":"image_load","product":"windows"}
- Potential RjvPlatform.DLL Sideloading From Non-Default Location · test · high · {"category":"image_load","product":"windows"}
- Potential RoboForm.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- DLL Sideloading Of ShellChromeAPI.DLL · test · high · {"category":"image_load","product":"windows"}
- Potential ShellDispatch.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential SmadHook.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential SolidPDFCreator.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Third Party Software DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Fax Service DLL Search Order Hijack · test · high · {"category":"image_load","product":"windows"}
- Potential Vcruntime140 DLL Sideloading · experimental · high · {"category":"image_load","product":"windows"}
- Potential Vivaldi_elf.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- VMGuestLib DLL Sideload · test · medium · {"category":"image_load","product":"windows"}
- VMMap Signed Dbghelp.DLL Potential Sideloading · test · medium · {"category":"image_load","product":"windows"}
- VMMap Unsigned Dbghelp.DLL Potential Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Via VMware Xfer · test · high · {"product":"windows","category":"image_load"}
- Potential Waveedit.DLL Sideloading · test · high · {"category":"image_load","product":"windows"}
- Potential Wazuh Security Platform DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Potential Mpclient.DLL Sideloading · test · high · {"product":"windows","category":"image_load"}
- Potential WWlib.DLL Sideloading · test · medium · {"category":"image_load","product":"windows"}
- Unsigned Module Loaded by ClickOnce Application · test · medium · {"category":"image_load","product":"windows"}
- Suspicious Unsigned Thor Scanner Execution · stable · high · {"category":"image_load","product":"windows"}
- UAC Bypass With Fake DLL · test · high · {"category":"image_load","product":"windows"}
- Potential DLL Sideloading Via DeviceEnroller.EXE · test · medium · {"category":"process_creation","product":"windows"}
- DLL Sideloading by VMware Xfer Utility · test · high · {"product":"windows","category":"process_creation"}
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE · test · high · {"category":"process_creation","product":"windows"}
- Suspicious GUP Usage · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Process of KeyScrambler.exe · test · medium · {"category":"process_creation","product":"windows"}
- Potential Mpclient.DLL Sideloading Via Defender Binaries · test · high · {"product":"windows","category":"process_creation"}
- Renamed Vmnat.exe Execution · test · high · {"category":"process_creation","product":"windows"}
- Tasks Folder Evasion · test · high · {"product":"windows","category":"process_creation"}
- Xwizard.EXE Execution From Non-Default Location · test · high · {"category":"process_creation","product":"windows"}
- DHCP Callout DLL Installation · test · high · {"category":"registry_set","product":"windows"}
- New DNS ServerLevelPluginDll Installed · test · high · {"product":"windows","category":"registry_set"}
- Registry Modification for OCI DLL Redirection · experimental · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0201 Detection Strategy for Hijack Execution Flow for DLLs
AN0577 Analytic 0577
DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Naikon · G0019
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Patchwork · G0040
- menuPass · G0045
- RTM · G0048
- APT32 · G0050
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- WIRTE · G0090
- GALLIUM · G0093
- APT41 · G0096
- BlackTech · G0098
- APT-C-36 · G0099
- Whitefly · G0107
- Chimera · G0114
- Evilnum · G0120
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Tonto Team · G0131
- BackdoorDiplomacy · G0135
- Aquatic Panda · G0143
- Earth Lusca · G1006
- SideCopy · G1008
- LuminousMoth · G1014
- FIN13 · G1016
- Cinnamon Tempest · G1021
- Daggerfly · G1034
- Storm-1811 · G1046
- Velvet Ant · G1047
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.