BigHugger
sk Skill · mukul975

detecting-dll-sideloading-attacks

Detect DLL side-loading and search-order hijacking (MITRE T1574) where adversaries plant malicious DLLs for legitimate signed applications to load, by analyzing Sysmon Event ID 7 DLL-load events, checking signatures/hashes against known-good versions, and flagging path anomalies with EDR tools like CrowdStrike, MDE, or SentinelOne. Use when investigating EDR alerts on unsigned DLLs, hunting for APT persistence via…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonproactive-detectionedrt1574defense-evasiondll-sideloadingmitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python