Detection of DLL Search Order Hijacking and Sideloading via Sysmon
This detection analytic identifies potential DLL search order hijacking by leveraging Sysmon to monitor for the loading of known vulnerable libraries from non-standard directory paths.
This brief focuses on the detection of DLL search order hijacking (T1574.001) and sideloading, techniques commonly used by threat actors to achieve code execution, escalate privileges, or maintain persistence on Windows systems. Attackers exploit the Windows DLL search order by placing a malicious, identically named DLL in a directory that is searched before the legitimate library path, or by dropping a malicious DLL in an application's execution directory to force it to load during startup. This analytic utilizes Sysmon Event ID 7 (Image Loaded) to track DLL loading events across the environment and cross-references them against a database of known hijackable libraries. By identifying when these specific libraries are loaded from non-standard locations, defenders can isolate potentially malicious activity within their endpoints. This detection is highly effective for identifying Living Off the Land (LotL) techniques and various malware families that utilize sideloading for defense evasion.
Impact
Successful exploitation allows attackers to gain arbitrary code execution in the context of a legitimate application, potentially leading to full system compromise, lateral movement, or long-term persistence. These techniques are frequently used in sophisticated intrusion campaigns and by various threat actors to bypass security controls.
Recommendation
Detection engineering teams should implement the provided Sysmon-based hunting logic to identify anomalous DLL loading patterns. Due to the potential for high noise, teams should perform an initial baselining of legitimate applications that load libraries from custom paths and tune exclusions accordingly.
- Enable Sysmon Event ID 7 logging across all endpoints to provide the telemetry required for this detection.
- Integrate the 'hijacklibs' research data (e.g., from hijacklibs.net) into the SIEM lookup table to cross-reference loaded DLLs.
- Prioritize investigating instances where DLLs known to be vulnerable to hijacking are loaded from user-writable directories (e.g., C:\Users\Public, C:\ProgramData).
Immediate actions
Deploy Sysmon with Event ID 7 configured
Threat Hunt
Search for DLL loads originating from user-writable directories
Data: Sysmon Event ID 7
Mitigations
Review and restrict write permissions on application installation directories
T1574.001
Detection coverage 1
Detect Known Hijackable DLLs Loaded from Non-Standard Paths
mediumDetects the loading of known hijackable DLLs from directories outside of System32, SysWOW64, and similar standard Windows paths using Sysmon Event ID 7.
Detection queries are available on the platform. Get full rules →