Title:Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution Status:test Description:Detects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory.
The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.
References: -https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/ Author: frack113 Date: 2022-03-06 modified:2023-08-03 Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection: selection: Image|endswith:'\OfflineScannerShell.exe'OriginalFileName:'OfflineScannerShell.exe'filter_main_legit_dir: CurrentDirectory:
'C:\Program Files\Windows Defender\Offline\' filter_main_empty: CurrentDirectory:
'' filter_main_null: CurrentDirectory:
'None' condition:selection and not 1 of filter_main_* Falsepositives:
-Unknown Level:medium