Cross-source coverage

T1073 / ATT&CK

DLL Side-Loading

ATT&CK has retired this technique. Rules still tag it; the current id is T1574.002 Hijack Execution Flow: DLL Side-Loading.

8 rules · 7 families across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Programs may specify DLLs that are loaded at runtime. Programs that improperly or vaguely specify a required DLL may be open to a vulnerability in which an unintended DLL is loaded. Side-loading vulnerabilities specifically occur when Windows Side-by-Side (WinSxS) manifests are not explicit enough about characteristics of the DLL to be loaded. Adversaries may take advantage of a legitimate program that is vulnerable to side-loading to load a malicious DLL.

Adversaries likely use this technique as a means of masking actions they perform under a legitimate, trusted system or software process.

Tactics
Stealth
Platforms
Windows
Telemetry

chronicle/detection-rules

4 rules
Detection Severity Format
abusing_azure_browser_sso Undefined YARA-L
notepadexe_dll_search_order_hijackingsysmon Undefined YARA-L
offensive_tool_maliciousdllgenerator_dll_side_loadingsysmon Undefined YARA-L
suspicious_gup_usage Undefined YARA-L

socfortress/Wazuh-Rules

4 rules · 3 families
Detection Severity Format
Sysmon - Event 10: ProcessAccess by · DLL Side-Loading (T1073) Low Wazuh XML
Sysmon - Event 1: Process creation · DLL Side-Loading (T1073) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · DLL Side-Loading (T1073) 2 variants Low Wazuh XML
Sysmon - Event 7: Image loaded by · DLL Side-Loading (T1073) Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.