Skip to content
Threat Feed
medium advisory

Detection of DLL Search Order Hijacking and Sideloading

This analytic identifies potential DLL sideloading or search order hijacking by monitoring for the loading of known abuse-prone DLLs from non-standard directory paths on Windows endpoints.

This detection focuses on identifying the abuse of DLL loading mechanisms, a common technique for persistence, privilege escalation, and defense evasion. Attackers place malicious DLLs in directories where applications look for dependencies, causing the application to load the attacker-controlled code instead of the legitimate library. This brief leverages research from hijacklibs.net to track known vulnerable DLLs and flag instances where they are loaded from unexpected locations. Defenders should note that this analytic requires Sysmon Event ID 7 to monitor image loads and relies on a reference lookup to distinguish between malicious and legitimate library loading patterns.

Impact

Successful exploitation allows attackers to gain persistence, elevate privileges within the context of a legitimate process, or bypass security controls by executing arbitrary code. This technique is frequently observed in post-exploitation scenarios, including those associated with previous SolarWinds exploitation events and broader Living Off the Land (LotL) campaigns.

Recommendation

  • Enable Sysmon Event ID 7 (Image Loaded) logging across all Windows endpoints to support this detection.
  • Implement the suggested lookup-based detection logic to compare loaded library names and paths against a known list of abuse-prone DLLs.
  • Tune the detection by adding process paths or specific library/application combinations that are known to be benign in your environment to the filter list.
  • Monitor the output for processes loading common DLLs from non-standard directories such as user profiles, temp folders, or writable application subdirectories.

Immediate actions

Deploy Sysmon Event ID 7 monitoring to capture library loads.

Detection Engineering 48h

Threat Hunt

Search for DLL loads originating from user-writable directories (e.g., AppData, Temp, ProgramData).

T1574.002 high high confidence hunt now

Data: Sysmon Event ID 7

Detection coverage 1

Detect DLLs with Known Abuse History Loaded from Suspicious Locations

medium

Detects loading of DLLs known to be used in sideloading attacks when loaded from non-standard directory locations.

sigma tactics: persistence, privilege-escalation techniques: T1574.001, T1574.002 sources: image_load, windows

Detection queries are available on the platform. Get full rules →