DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
Description
Detects a threat actor creating a file named iertutil.dll in the C:\Program Files\Internet Explorer\ directory over the network for a DCOM InternetExplorer DLL Hijack scenario.
Query · sigma
selection: EventID: 5145 RelativeTargetName|endswith: \Internet Explorer\iertutil.dll filter: SubjectUserName|endswith: $ condition: selection and not filter
Known false positives
- Unknown