AN0577
Analytic 0577
Windows
DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=15
WinEventLog:Sysmon
EventCode=7
WinEventLog:Security
EventCode=4657
WinEventLog:Sysmon
EventCode=1
[AllowedDllPaths]
Known safe DLL directories to suppress false positives (e.g., C:\Windows\System32).
[ProcessAllowList]
Applications expected to load DLLs from non-standard locations (e.g., development tools).
[TimeWindow]
Correlation interval between DLL file creation, registry changes, and module load.
[HashBaseline]
Baseline hashes for legitimate DLLs used to detect substitution.