Cross-source coverage
T1073 / ATT&CK
DLL Side-Loading
ATT&CK has retired this technique. Rules still tag it; the current id is T1574.002 Hijack Execution Flow: DLL Side-Loading.
8 rules · 7 families across 2 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Programs may specify DLLs that are loaded at runtime. Programs that improperly or vaguely specify a required DLL may be open to a vulnerability in which an unintended DLL is loaded. Side-loading vulnerabilities specifically occur when Windows Side-by-Side (WinSxS) manifests are not explicit enough about characteristics of the DLL to be loaded. Adversaries may take advantage of a legitimate program that is vulnerable to side-loading to load a malicious DLL.
Adversaries likely use this technique as a means of masking actions they perform under a legitimate, trusted system or software process.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
- —
chronicle/detection-rules
4 rules| Detection | Severity | Format |
|---|---|---|
| abusing_azure_browser_sso | Undefined | YARA-L |
| notepadexe_dll_search_order_hijackingsysmon | Undefined | YARA-L |
| offensive_tool_maliciousdllgenerator_dll_side_loadingsysmon | Undefined | YARA-L |
| suspicious_gup_usage | Undefined | YARA-L |
socfortress/Wazuh-Rules
4 rules · 3 families| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 10: ProcessAccess by · DLL Side-Loading (T1073) | Low | Wazuh XML |
| Sysmon - Event 1: Process creation · DLL Side-Loading (T1073) 2 variants | Low | Wazuh XML |
| Sysmon - Event 1: Process creation · DLL Side-Loading (T1073) 2 variants | Low | Wazuh XML |
| Sysmon - Event 7: Image loaded by · DLL Side-Loading (T1073) | Low | Wazuh XML |