Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0201 — Detection Strategy for Hijack Execution Flow for DLLs
DET0201

Detection Strategy for Hijack Execution Flow for DLLs

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0577 Analytic 0577
Windows

DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=15 WinEventLog:Sysmon EventCode=7 WinEventLog:Security EventCode=4657 WinEventLog:Sysmon EventCode=1
[AllowedDllPaths] Known safe DLL directories to suppress false positives (e.g., C:\Windows\System32).
[ProcessAllowList] Applications expected to load DLLs from non-standard locations (e.g., development tools).
[TimeWindow] Correlation interval between DLL file creation, registry changes, and module load.
[HashBaseline] Baseline hashes for legitimate DLLs used to detect substitution.

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0201
STIX ID
x-mitre-detection-strategy--bd33de0c-1ed7-42ea-b77d-1fd5d33acd3b
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.