Skip to content
Threat Feed
medium advisory

Detection of Known Abused DLLs in Suspicious Locations

This detection identifies the creation of DLLs with a history of exploitation within common writable directories, providing visibility into potential DLL sideloading and search order hijacking attempts.

This brief addresses the detection of DLL sideloading and search order hijacking, common techniques employed by threat actors to execute arbitrary code, maintain persistence, or escalate privileges within a Windows environment. By monitoring for the creation of DLLs known to be vulnerable to hijacking when placed in atypical, user-writable directories such as \Users\, \Windows\Temp\, or \ProgramData\, security teams can identify malicious activity that attempts to blend in with legitimate system operations. This detection logic relies on EDR telemetry, specifically filesystem events, and cross-references file names against known databases of hijackable libraries. Effective implementation requires the ingestion of detailed process and filesystem telemetry, typically via Sysmon or native EDR sensors, and necessitates careful tuning to account for legitimate software behaviors that may generate false positives in these paths.

Impact

Successful exploitation of DLL sideloading can allow an attacker to achieve code execution under the context of a legitimate process, potentially bypassing security controls, gaining persistence, or elevating privileges to SYSTEM. This technique is frequently observed in post-exploitation phases to maintain long-term access and facilitate lateral movement across the network.

Recommendation

  • Deploy the provided Sigma rule to detect the creation of known vulnerable DLLs in common abuse locations.
  • Integrate endpoint filesystem telemetry (Sysmon Event ID 11) into your SIEM, ensuring complete mapping to the Endpoint data model.
  • Establish a baseline of known-good software installation directories and whitelist legitimate application-specific DLLs to reduce the false positive rate.
  • Prioritize investigation of alerts that show a suspicious parent process associated with the file creation event.

Immediate actions

Deploy the detection rule for suspicious DLL creation.

Detection Engineering 48h

Threat Hunt

Filesystem events in user-writable paths filtering for .dll extensions.

T1574 medium medium confidence hunt now

Data: Sysmon Event ID 11

Mitigations

Review and restrict write permissions on critical Windows directories.

short_term IT Operations

T1574.001

Detection coverage 1

Detect Creation of Known Abused DLLs in Suspicious Paths

medium

Detects the creation of DLLs that are known to be used for sideloading/hijacking when written to common writable directories.

sigma tactics: persistence techniques: T1574.001, T1574.002 sources: file_event, windows

Detection queries are available on the platform. Get full rules →