Skip to content
Threat Feed

Tag

Dll Side-Loading

4 briefs RSS
medium advisory

Potential DLL Side-Loading via Trusted Microsoft Programs

This rule detects potential DLL side-loading attempts by identifying instances of Windows trusted programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) being started after being renamed or from a non-standard path, which is a common technique to evade defenses by side-loading a malicious DLL into the memory space of a trusted process.

WinWord.exe +4 defense-evasion execution dll-side-loading windows
2r 2t
high advisory

Untrusted DLL Loaded by Azure AD Connect Authentication Agent

The loading of an untrusted DLL by the Azure AD Connect Authentication Agent, potentially indicating credential access attempts via the Pass-through Authentication service, is detected by this rule.

Azure AD Connect Authentication Agent credential-access dll-side-loading azure-ad-connect
2r 1t
medium advisory

Potential DLL Side-Loading via Trusted Microsoft Programs

This rule detects potential DLL side-loading attempts by identifying trusted Microsoft programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) running from non-standard paths or after being renamed to evade defenses.

Microsoft Word +2 defense-evasion execution windows dll side-loading
2r 2t
high advisory

Suspicious Microsoft Antimalware Service Execution

Detection of Microsoft Antimalware Service Executable (MsMpEng.exe) executing from non-standard paths or being renamed, indicative of defense evasion via DLL side-loading or process masquerading.

Microsoft Antimalware Service defense-evasion execution masquerading dll-side-loading windows
2r 3t