Skip to content
Threat Feed
medium advisory

Detection of DLL Search Order Hijacking and Sideloading via Sysmon

This detection analytic identifies potential DLL search order hijacking by leveraging Sysmon to monitor for the loading of known vulnerable libraries from non-standard directory paths.

This brief focuses on the detection of DLL search order hijacking (T1574.001) and sideloading, techniques commonly used by threat actors to achieve code execution, escalate privileges, or maintain persistence on Windows systems. Attackers exploit the Windows DLL search order by placing a malicious, identically named DLL in a directory that is searched before the legitimate library path, or by dropping a malicious DLL in an application's execution directory to force it to load during startup. This analytic utilizes Sysmon Event ID 7 (Image Loaded) to track DLL loading events across the environment and cross-references them against a database of known hijackable libraries. By identifying when these specific libraries are loaded from non-standard locations, defenders can isolate potentially malicious activity within their endpoints. This detection is highly effective for identifying Living Off the Land (LotL) techniques and various malware families that utilize sideloading for defense evasion.

Impact

Successful exploitation allows attackers to gain arbitrary code execution in the context of a legitimate application, potentially leading to full system compromise, lateral movement, or long-term persistence. These techniques are frequently used in sophisticated intrusion campaigns and by various threat actors to bypass security controls.

Recommendation

Detection engineering teams should implement the provided Sysmon-based hunting logic to identify anomalous DLL loading patterns. Due to the potential for high noise, teams should perform an initial baselining of legitimate applications that load libraries from custom paths and tune exclusions accordingly.

  • Enable Sysmon Event ID 7 logging across all endpoints to provide the telemetry required for this detection.
  • Integrate the 'hijacklibs' research data (e.g., from hijacklibs.net) into the SIEM lookup table to cross-reference loaded DLLs.
  • Prioritize investigating instances where DLLs known to be vulnerable to hijacking are loaded from user-writable directories (e.g., C:\Users\Public, C:\ProgramData).

Immediate actions

Deploy Sysmon with Event ID 7 configured

IT Operations 72h

Threat Hunt

Search for DLL loads originating from user-writable directories

T1574.001 high high confidence hunt now

Data: Sysmon Event ID 7

Mitigations

Review and restrict write permissions on application installation directories

medium_term IT Security

T1574.001

Detection coverage 1

Detect Known Hijackable DLLs Loaded from Non-Standard Paths

medium

Detects the loading of known hijackable DLLs from directories outside of System32, SysWOW64, and similar standard Windows paths using Sysmon Event ID 7.

sigma tactics: defense_evasion techniques: T1574.001 sources: image_load, windows

Detection queries are available on the platform. Get full rules →