This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential DLL Sideloading Of MsCorSvc.DLL
Original Source:
[Sigma source]
Title:
Potential DLL Sideloading Of MsCorSvc.DLL
Status:
test
Description:
Detects potential DLL sideloading of "mscorsvc.dll".
References:
-https://hijacklibs.net/entries/microsoft/built-in/mscorsvc.html
Author:
Wietze Beukema
Date:
2024-07-11
modified:
2025-02-26
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.001'
Logsource:
product: windows
category: image_load
Detection:
selection:
ImageLoaded|endswith
:
'\mscorsvc.dll'
filter_main_generic:
ImageLoaded|startswith
:
-'C:\Windows\Microsoft.NET\Framework\'
-'C:\Windows\Microsoft.NET\Framework64\'
-'C:\Windows\Microsoft.NET\FrameworkArm\'
-'C:\Windows\Microsoft.NET\FrameworkArm64\'
-'C:\Windows\WinSxS\'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Legitimate applications loading their own versions of the DLL mentioned in this rule.
Level:
medium