Files
splunk-security_content/lookups/hijacklibs_loaded.csv
2024-03-20 20:01:18 +00:00

99 KiB

1islibrarylibraryexcludesttpcomment
2TRUEaclui.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
3TRUEaclui.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
4TRUEacrodistdll.dll*\Program Files\Adobe\Acrobat *T1574.002https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
5TRUEacrodistdll.dll*\Acrobat\acrodistdll*T1574.002https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
6TRUEactiveds.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
7TRUEactiveds.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
8TRUEadsldpc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
9TRUEadsldpc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
10TRUEaepic.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
11TRUEaepic.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
12TRUEapphelp.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
13TRUEapphelp.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
14TRUEapplicationframe.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
15TRUEapplicationframe.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
16TRUEappvpolicy.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
17TRUEappwiz.cpl*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
18TRUEappwiz.cpl*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
19TRUEappxalluserstore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
20TRUEappxalluserstore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
21TRUEappxdeploymentclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
22TRUEappxdeploymentclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
23TRUEarchiveint.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
24TRUEarchiveint.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
25TRUEashldres.dll*\Program Files\McAfee.com\VSO*T1574.002https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf
26TRUEatl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
27TRUEatl.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
28TRUEatltracetoolui.dll*\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
29TRUEaudioses.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
30TRUEaudioses.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
31TRUEauditpolcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
32TRUEauditpolcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
33TRUEauthfwcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
34TRUEauthfwcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
35TRUEauthz.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
36TRUEauthz.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
37TRUEavrt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
38TRUEavrt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
39TRUEbasicnetutils.dll*\Appdata\local\Temp\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
40TRUEbasicnetutils.dll*\Program Files\BAIDU\BAIDUPINYIN\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
41TRUEbatmeter.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
42TRUEbatmeter.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
43TRUEbcd.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
44TRUEbcd.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
45TRUEbcp47langs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
46TRUEbcp47langs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
47TRUEbcp47mrm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
48TRUEbcp47mrm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
49TRUEbcrypt.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
50TRUEbcrypt.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
51TRUEbderepair.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
52TRUEbootmenuux.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
53TRUEbootux.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
54TRUEcabinet.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
55TRUEcabinet.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
56TRUEcabview.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
57TRUEcabview.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
58TRUEcertcli.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
59TRUEcertcli.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
60TRUEcertenroll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
61TRUEcertenroll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
62TRUEcfgmgr32.dll*\Windows\System32\*T1574.002
63TRUEcfgmgr32.dll*\Windows\SysWOW64\*T1574.002
64TRUEchrome_frame_helper.dll*\Appdata\local\Google\Chrome\Application*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
65TRUEchrome_frame_helper.dll*\Program Files\Google\Chrome\Application*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
66TRUEciscosparklauncher.dll*\Appdata\local\CiscoSparkLauncher*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
67TRUEciscosparklauncher.dll*\AppData\Local\Programs\Cisco Spark\*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
68TRUEclassicexplorer32.dll*\Program Files\Classic Shell*T1574.002https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
69TRUEclassicexplorer32.dll*\Program Files\Open-Shell*T1574.002https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
70TRUEcldapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
71TRUEcldapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
72TRUEclipc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
73TRUEclipc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
74TRUEclusapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
75TRUEclusapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
76TRUEcmpbk32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
77TRUEcmpbk32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
78TRUEcmutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
79TRUEcmutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
80TRUEcoloradapterclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
81TRUEcoloradapterclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
82TRUEcolorui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
83TRUEcolorui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
84TRUEcomdlg32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
85TRUEcomdlg32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
86TRUEcommfunc.dll*\Program Files\Lenovo\Communications Utility*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
87TRUEconfigmanager2.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
88TRUEconnect.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
89TRUEconnect.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
90TRUEcoredplus.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
91TRUEcoremessaging.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
92TRUEcoremessaging.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
93TRUEcoreuicomponents.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
94TRUEcoreuicomponents.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
95TRUEcredui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
96TRUEcredui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
97TRUEcryptbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
98TRUEcryptbase.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
99TRUEcryptdll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
100TRUEcryptdll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
101TRUEcryptsp.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
102TRUEcryptsp.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
103TRUEcryptui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
104TRUEcryptui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
105TRUEcryptxml.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
106TRUEcryptxml.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
107TRUEcscapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
108TRUEcscapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
109TRUEcscobj.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
110TRUEcscobj.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
111TRUEcscui.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
112TRUEcscui.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
113TRUEd2d1.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
114TRUEd2d1.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
115TRUEd3d10.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
116TRUEd3d10.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
117TRUEd3d10_1.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
118TRUEd3d10_1.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
119TRUEd3d10_1core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
120TRUEd3d10_1core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
121TRUEd3d10core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
122TRUEd3d10core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
123TRUEd3d10warp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
124TRUEd3d10warp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
125TRUEd3d11.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
126TRUEd3d11.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
127TRUEd3d12.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
128TRUEd3d12.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
129TRUEd3d9.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
130TRUEd3d9.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
131TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\bin\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
132TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\bin\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
133TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\redist\d3d\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
134TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\redist\d3d\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
135TRUEd3dcompiler_47.dll*\Program Files\wireshark*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
136TRUEd3dcompiler_47.dll*\Program Files\cisco systems\cisco jabber*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
137TRUEd3dcompiler_47.dll*\Program Files\microsoft\edge\application\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
138TRUEd3dcompiler_47.dll*\Program Files\Google\Chrome\Application\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
139TRUEd3dcompiler_47.dll*\Appdata\local\microsoft\teams\stage*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
140TRUEd3dcompiler_47.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
141TRUEd3dcompiler_47.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
142TRUEd3dcompiler_47.dll*\Microsoft\Teams\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
143TRUEd3dx9_43.dll*\Windows\System32\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
144TRUEd3dx9_43.dll*\Windows\SysWOW64\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
145TRUEdataexchange.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
146TRUEdataexchange.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
147TRUEdavclnt.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
148TRUEdavclnt.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
149TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
150TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
151TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
152TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
153TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
154TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
155TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
156TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x86\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
157TRUEdbgcore.dll*\Program Files\microsoft office\root\office*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
158TRUEdbgcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
159TRUEdbgcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
160TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
161TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
162TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
163TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
164TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
165TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
166TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
167TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
168TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
169TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
170TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
171TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x86\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
172TRUEdbghelp.dll*\Program Files\cisco systems\cisco jabber*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
173TRUEdbghelp.dll*\Program Files\microsoft office\root\office*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
174TRUEdbghelp.dll*\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
175TRUEdbghelp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
176TRUEdbghelp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
177TRUEdbgmodel.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
178TRUEdbgmodel.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
179TRUEdbgmodel.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
180TRUEdcntel.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
181TRUEdcomp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
182TRUEdcomp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
183TRUEdefragproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
184TRUEdefragproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
185TRUEdesktopshellext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
186TRUEdesktopshellext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
187TRUEdeviceassociation.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
188TRUEdeviceassociation.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
189TRUEdevicecredential.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
190TRUEdevicecredential.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
191TRUEdevicepairing.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
192TRUEdevicepairing.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
193TRUEdevobj.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
194TRUEdevobj.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
195TRUEdevrtl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
196TRUEdevrtl.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
197TRUEdhcpcmonitor.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
198TRUEdhcpcmonitor.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
199TRUEdhcpcsvc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
200TRUEdhcpcsvc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
201TRUEdhcpcsvc6.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
202TRUEdhcpcsvc6.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
203TRUEdirectmanipulation.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
204TRUEdirectmanipulation.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
205TRUEdismapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
206TRUEdismapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
207TRUEdismcore.dll*\Windows\System32\dism*T1574.001https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
208TRUEdismcore.dll*\Windows\SysWOW64\dism*T1574.001https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
209TRUEdmcfgutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
210TRUEdmcfgutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
211TRUEdmcmnutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
212TRUEdmcmnutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
213TRUEdmcommandlineutils.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
214TRUEdmcommandlineutils.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
215TRUEdmenrollengine.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
216TRUEdmenrollengine.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
217TRUEdmenterprisediagnostics.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
218TRUEdmiso8601utils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
219TRUEdmiso8601utils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
220TRUEdmoleaututils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
221TRUEdmoleaututils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
222TRUEdmprocessxmlfiltered.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
223TRUEdmprocessxmlfiltered.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
224TRUEdmpushproxy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
225TRUEdmpushproxy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
226TRUEdmxmlhelputils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
227TRUEdmxmlhelputils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
228TRUEdnsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
229TRUEdnsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
230TRUEdot3api.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
231TRUEdot3api.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
232TRUEdot3cfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
233TRUEdot3cfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
234TRUEdpx.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
235TRUEdpx.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
236TRUEdrprov.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
237TRUEdrprov.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
238TRUEdrvstore.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
239TRUEdrvstore.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
240TRUEdsclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
241TRUEdsclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
242TRUEdsparse.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
243TRUEdsparse.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
244TRUEdsprop.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
245TRUEdsprop.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
246TRUEdsreg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
247TRUEdsreg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
248TRUEdsrole.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
249TRUEdsrole.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
250TRUEdui70.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
251TRUEdui70.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
252TRUEduser.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
253TRUEduser.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
254TRUEdusmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
255TRUEdusmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
256TRUEdwmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
257TRUEdwmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
258TRUEdwmcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
259TRUEdwrite.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
260TRUEdwrite.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
261TRUEdxcore.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
262TRUEdxcore.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
263TRUEdxgi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
264TRUEdxgi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
265TRUEdxva2.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
266TRUEdxva2.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
267TRUEdynamoapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
268TRUEeappcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
269TRUEeappcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
270TRUEeappprxy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
271TRUEeappprxy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
272TRUEedgeiso.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
273TRUEedgeiso.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
274TRUEedputil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
275TRUEedputil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
276TRUEefsadu.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
277TRUEefsadu.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
278TRUEefsutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
279TRUEefsutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
280TRUEesent.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
281TRUEesent.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
282TRUEexecmodelproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
283TRUEexecmodelproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
284TRUEexplorerframe.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
285TRUEexplorerframe.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
286TRUEfacesdk.dll*\Program Files\luxand\facesdk\bin\win64*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
287TRUEfastprox.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
288TRUEfastprox.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
289TRUEfaultrep.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
290TRUEfaultrep.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
291TRUEfddevquery.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
292TRUEfddevquery.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
293TRUEfeclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
294TRUEfeclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
295TRUEfhcfg.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
296TRUEfhcfg.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
297TRUEfhsvcctl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
298TRUEfirewallapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
299TRUEfirewallapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
300TRUEflightsettings.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
301TRUEflightsettings.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
302TRUEfltlib.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
303TRUEfltlib.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
304TRUEformdll.dll*\Program Files\Common Files\Microsoft Shared\NoteSync Forms*T1574.002https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1
305TRUEframedynos.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
306TRUEframedynos.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
307TRUEfveapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
308TRUEfveapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
309TRUEfveskybackup.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
310TRUEfvewiz.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
311TRUEfwbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
312TRUEfwbase.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
313TRUEfwcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
314TRUEfwcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
315TRUEfwpolicyiomgr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
316TRUEfwpolicyiomgr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
317TRUEfwpuclnt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
318TRUEfwpuclnt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
319TRUEfxsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
320TRUEfxsapi.dll*\Windows\System32\driverstore\filerepository\prnms002.inf_*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
321TRUEfxsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
322TRUEfxsst.dll*\Windows\System32\*T1574.001https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/
323TRUEfxstiff.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
324TRUEfxstiff.dll*\Windows\System32\driverstore\filerepository\prnms002.inf_*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
325TRUEgetuname.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
326TRUEgetuname.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
327TRUEgflagsui.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
328TRUEglib-2.0.dll*\Program Files\VMware\VMware Tools*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
329TRUEglib-2.0.dll*\Program Files\VMware\VMware Workstation*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
330TRUEglib-2.0.dll*\Program Files\VMware\VMware Player*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
331TRUEgpapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
332TRUEgpapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
333TRUEhha.dll*\Windows\System32\*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
334TRUEhha.dll*\Windows\SysWOW64\*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
335TRUEhha.dll*\Program Files\HTML Help Workshop*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
336TRUEhid.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
337TRUEhid.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
338TRUEhnetmon.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
339TRUEhnetmon.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
340TRUEhpcustpartui.dll*\Program Files\HP*T1574.002https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html
341TRUEhpqhvsei.dll*\Program Files\HP*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
342TRUEhttpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
343TRUEhttpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
344TRUEicmp.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
345TRUEicmp.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
346TRUEidstore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
347TRUEidstore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
348TRUEieadvpack.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
349TRUEieadvpack.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
350TRUEiedkcs32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
351TRUEiedkcs32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
352TRUEiernonce.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
353TRUEiernonce.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
354TRUEiertutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
355TRUEiertutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
356TRUEifmon.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
357TRUEifmon.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
358TRUEifsutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
359TRUEifsutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
360TRUEinproclogger.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
361TRUEiphlpapi.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
362TRUEiphlpapi.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
363TRUEiri.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
364TRUEiri.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
365TRUEiscsidsc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
366TRUEiscsidsc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
367TRUEiscsiexe.dll*\Windows\System32\*T1574.001https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
368TRUEiscsiexe.dll*\Windows\SysWOW64\*T1574.001https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
369TRUEiscsium.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
370TRUEiscsium.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
371TRUEisv.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
372TRUEisv.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
373TRUEiumbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
374TRUEiumsdk.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
375TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
376TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
377TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
378TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
379TRUEjoinutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
380TRUEjoinutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
381TRUEkdstub.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
382TRUEksuser.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
383TRUEksuser.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
384TRUEktmw32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
385TRUEktmw32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
386TRUEldvpocx.ocx*\Program Files\Symantec_Client_Security\Symantec AntiVirus*T1574.002https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
387TRUEldvpocx.ocx*\Program Files\Symantec AntiVirus*T1574.002https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
388TRUElibvlc.dll*\Program Files\VideoLAN\VLC*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
389TRUElicensemanagerapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
390TRUElicensemanagerapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
391TRUElicensingdiagspp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
392TRUElicensingdiagspp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
393TRUElinkinfo.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
394TRUElinkinfo.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
395TRUElmiguardiandll.dll*\Program Files\LogMeIn*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
396TRUElmiguardiandll.dll*\Program Files\LogMeIn\x86*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
397TRUElmiguardiandll.dll*\Program Files\LogMeIn\x64*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
398TRUEloadperf.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
399TRUEloadperf.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
400TRUElockdown.dll*\Program Files\McAfee\VirusScan Enterprise*T1574.002https://twitter.com/thepacketrat/status/1520878930449817600
401TRUElockhostingframework.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
402TRUElog.dll*\Program Files\Bitdefender Antivirus Free*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
403TRUElogoncli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
404TRUElogoncli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
405TRUElogoncontroller.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
406TRUElogoncontroller.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
407TRUElpksetupproxyserv.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
408TRUElpksetupproxyserv.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
409TRUElrwizdll.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
410TRUEmagnification.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
411TRUEmagnification.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
412TRUEmaintenanceui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
413TRUEmapistub.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
414TRUEmapistub.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
415TRUEmbaexmlparser.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
416TRUEmdmdiagnostics.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
417TRUEmfc42u.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
418TRUEmfc42u.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
419TRUEmfcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
420TRUEmfcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
421TRUEmfplat.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
422TRUEmfplat.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
423TRUEmi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
424TRUEmi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
425TRUEmidimap.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
426TRUEmidimap.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
427TRUEmintdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
428TRUEmiutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
429TRUEmiutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
430TRUEmlang.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
431TRUEmlang.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
432TRUEmmdevapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
433TRUEmmdevapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
434TRUEmobilenetworking.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
435TRUEmobilenetworking.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
436TRUEmozglue.dll*\Program Files\SeaMonkey*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
437TRUEmozglue.dll*\Program Files\Mozilla Firefox*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
438TRUEmozglue.dll*\Program Files\Mozilla Thunderbird*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
439TRUEmozglue.dll*\AppData\Local\Mozilla Firefox\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
440TRUEmpclient.dll*\Program Files\Windows Defender*T1574.002https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
441TRUEmpclient.dll*\ProgramData\Microsoft\Windows Defender\Platform\*T1574.002https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
442TRUEmpr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
443TRUEmpr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
444TRUEmprapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
445TRUEmprapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
446TRUEmpsvc.dll*\Program Files\Windows Defender\*T1574.002https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
447TRUEmpsvc.dll*\ProgramData\Microsoft\Windows Defender\Platform\*T1574.002https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
448TRUEmrmcorer.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
449TRUEmrmcorer.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
450TRUEmsacm32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
451TRUEmsacm32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
452TRUEmscms.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
453TRUEmscms.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
454TRUEmscoree.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
455TRUEmscoree.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
456TRUEmscorsvc.dll*\Windows\Microsoft.NET\Framework\v*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
457TRUEmscorsvc.dll*\Windows\Microsoft.NET\Framework64\v*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
458TRUEmsctf.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
459TRUEmsctf.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
460TRUEmsctfmonitor.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
461TRUEmsctfmonitor.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
462TRUEmsdrm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
463TRUEmsdrm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
464TRUEmsdtctm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
465TRUEmsftedit.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
466TRUEmsftedit.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
467TRUEmsi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
468TRUEmsi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
469TRUEmsiso.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
470TRUEmsiso.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
471TRUEmsutb.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
472TRUEmsutb.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
473TRUEmsvcp110_win.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
474TRUEmsvcp110_win.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
475TRUEmsvcr100.dll*\Windows\System32\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
476TRUEmsvcr100.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
477TRUEmswb7.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
478TRUEmswb7.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
479TRUEmswsock.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
480TRUEmswsock.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
481TRUEmsxml3.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
482TRUEmsxml3.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
483TRUEmtxclu.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
484TRUEmtxclu.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
485TRUEnapinsp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
486TRUEnapinsp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
487TRUEncrypt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
488TRUEncrypt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
489TRUEndfapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
490TRUEndfapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
491TRUEnetapi32.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
492TRUEnetapi32.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
493TRUEnetid.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
494TRUEnetid.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
495TRUEnetiohlp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
496TRUEnetiohlp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
497TRUEnetjoin.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
498TRUEnetjoin.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
499TRUEnetplwiz.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
500TRUEnetplwiz.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
501TRUEnetprofm.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
502TRUEnetprofm.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
503TRUEnetprovfw.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
504TRUEnetprovfw.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
505TRUEnetsetupapi.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
506TRUEnetsetupapi.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
507TRUEnetshell.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
508TRUEnetshell.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
509TRUEnettrace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
510TRUEnetutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
511TRUEnetutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
512TRUEnetworkexplorer.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
513TRUEnetworkexplorer.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
514TRUEnewdev.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
515TRUEnewdev.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
516TRUEninput.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
517TRUEninput.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
518TRUEnlaapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
519TRUEnlaapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
520TRUEnlansp_c.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
521TRUEnlansp_c.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
522TRUEnpmproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
523TRUEnpmproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
524TRUEnshhttp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
525TRUEnshhttp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
526TRUEnshipsec.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
527TRUEnshipsec.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
528TRUEnshwfp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
529TRUEnshwfp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
530TRUEntdsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
531TRUEntdsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
532TRUEntlanman.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
533TRUEntlanman.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
534TRUEntlmshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
535TRUEntlmshared.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
536TRUEntmarta.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
537TRUEntmarta.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
538TRUEntshrui.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
539TRUEntshrui.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
540TRUEnvsmartmax.dll*\Program Files\NVIDIA Corporation\Display*T1574.002https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
541TRUEoleacc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
542TRUEoleacc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
543TRUEomadmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
544TRUEomadmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
545TRUEonex.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
546TRUEonex.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
547TRUEopcservices.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
548TRUEopcservices.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
549TRUEopera_elf.dll*\Appdata\local\programs\opera\*T1574.002https://twitter.com/ShitSecure/status/1566127363389329412
550TRUEosbaseln.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
551TRUEosbaseln.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
552TRUEosksupport.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
553TRUEosuninst.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
554TRUEosuninst.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
555TRUEoutllib.dll*\Program Files\Microsoft Office\OFFICE*T1574.002https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
556TRUEoutllib.dll*\Program Files\Microsoft Office\Root\OFFICE*T1574.002https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
557TRUEp2p.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
558TRUEp2p.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
559TRUEp2pnetsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
560TRUEp2pnetsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
561TRUEp9np.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
562TRUEp9np.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
563TRUEpcaui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
564TRUEpcaui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
565TRUEpdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
566TRUEpdh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
567TRUEpeerdistsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
568TRUEpeerdistsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
569TRUEpkeyhelper.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
570TRUEpla.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
571TRUEpla.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
572TRUEplaysndsrv.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
573TRUEplaysndsrv.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
574TRUEpnrpnsp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
575TRUEpnrpnsp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
576TRUEpolicymanager.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
577TRUEpolicymanager.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
578TRUEpolstore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
579TRUEpolstore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
580TRUEpowrprof.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
581TRUEpowrprof.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
582TRUEprintui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
583TRUEprintui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
584TRUEprntvpt.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
585TRUEprntvpt.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
586TRUEprofapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
587TRUEprofapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
588TRUEpropsys.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
589TRUEpropsys.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
590TRUEproximitycommon.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
591TRUEproximitycommon.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
592TRUEproximityservicepal.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
593TRUEprvdmofcomp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
594TRUEprvdmofcomp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
595TRUEpuiapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
596TRUEpuiapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
597TRUEpython39.dll*\Program Files\Python39*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
598TRUEpython39.dll*\Appdata\local\Temp\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
599TRUEpython39.dll*\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
600TRUEpython39.dll*\Users\anaconda3*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
601TRUEqrt.dll*\Program Files\F-Secure\Anti-Virus*T1574.002https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
602TRUEradcui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
603TRUEradcui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
604TRUErasapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
605TRUErasapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
606TRUErasdlg.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
607TRUErasdlg.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
608TRUErasgcw.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
609TRUErasgcw.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
610TRUErasman.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
611TRUErasman.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
612TRUErasmontr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
613TRUErasmontr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
614TRUErastls.dll*\Program Files\Symantec\Network Connected Devices Auto Setup*T1574.002https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf
615TRUErcdll.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
616TRUEreagent.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
617TRUEreagent.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
618TRUEregapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
619TRUEregapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
620TRUEreseteng.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
621TRUEresetengine.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
622TRUEresutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
623TRUEresutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
624TRUErjvplatform.dll*\Windows\System32\SystemResetPlatform*T1574.002https://twitter.com/0gtweet/status/1666716511988330499
625TRUErjvplatform.dll*\Windows\SysWOW64\SystemResetPlatform*T1574.002https://twitter.com/0gtweet/status/1666716511988330499
626TRUErmclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
627TRUErmclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
628TRUErpcnsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
629TRUErpcnsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
630TRUErsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
631TRUErsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
632TRUErtutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
633TRUErtutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
634TRUErtworkq.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
635TRUErtworkq.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
636TRUErzlog4cpp_logger.dll*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*T1574.002https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
637TRUEsafestore32.dll*\Program Files\Sophos\Sophos Anti-Virus*T1574.002https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
638TRUEsamcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
639TRUEsamcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
640TRUEsamlib.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
641TRUEsamlib.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
642TRUEsapi_onecore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
643TRUEsapi_onecore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
644TRUEsas.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
645TRUEsas.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
646TRUEscansetting.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
647TRUEscansetting.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
648TRUEscecli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
649TRUEscecli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
650TRUEschedcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
651TRUEschedcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
652TRUEsecur32.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
653TRUEsecur32.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
654TRUEsecurity.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
655TRUEsecurity.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
656TRUEsensapi.dll*\Windows\System32\*T1574.002https://twitter.com/AndrewOliveau/status/1682185200862625792
657TRUEsensapi.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/AndrewOliveau/status/1682185200862625792
658TRUEshell32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
659TRUEshell32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
660TRUEshfolder.dll*\Windows\System32\*T1574.002https://twitter.com/dissectmalware/status/978017957480628226
661TRUEshfolder.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/dissectmalware/status/978017957480628226
662TRUEsiteadv.dll*\Program Files\SiteAdvisor\*T1574.002https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf
663TRUEslc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
664TRUEslc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
665TRUEsmadhook32c.dll*\Program Files\Smadav*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
666TRUEsnmpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
667TRUEsnmpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
668TRUEspectrumsyncclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
669TRUEspp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
670TRUEspp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
671TRUEsppc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
672TRUEsppc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
673TRUEsppcext.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
674TRUEsppcext.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
675TRUEsrclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
676TRUEsrclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
677TRUEsrcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
678TRUEsrmtrace.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
679TRUEsrmtrace.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
680TRUEsrpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
681TRUEsrpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
682TRUEsrvcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
683TRUEsrvcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
684TRUEssp.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
685TRUEssp.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
686TRUEssp_isv.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
687TRUEssp_isv.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
688TRUEsspicli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
689TRUEsspicli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
690TRUEssshim.dll*\Windows\System32\*T1574.002https://twitter.com/0gtweet/status/1363107343018385410
691TRUEssshim.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/0gtweet/status/1363107343018385410
692TRUEstaterepository.core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
693TRUEstaterepository.core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
694TRUEstructuredquery.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
695TRUEstructuredquery.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
696TRUEsxshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
697TRUEsxshared.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
698TRUEsymsrv.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
699TRUEsystemsettingsthresholdadminflowui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
700TRUEtapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
701TRUEtapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
702TRUEtbs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
703TRUEtbs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
704TRUEtdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
705TRUEtdh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
706TRUEtextshaping.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
707TRUEtextshaping.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
708TRUEtimesync.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
709TRUEtmdbglog.dll*\Program Files\Trend Micro\Titanium*T1574.002https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/
710TRUEtosbtkbd.dll*\Program Files\Toshiba\Bluetooth Toshiba Stack*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
711TRUEtpmcoreprovisioning.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
712TRUEtpmcoreprovisioning.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
713TRUEtquery.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
714TRUEtquery.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
715TRUEtsworkspace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
716TRUEtsworkspace.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
717TRUEttdrecord.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
718TRUEttdrecord.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
719TRUEtwext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
720TRUEtwext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
721TRUEtwinapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
722TRUEtwinapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
723TRUEtwinui.appcore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
724TRUEtwinui.appcore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
725TRUEuianimation.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
726TRUEuianimation.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
727TRUEuiautomationcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
728TRUEuiautomationcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
729TRUEuireng.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
730TRUEuireng.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
731TRUEuiribbon.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
732TRUEuiribbon.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
733TRUEumpdc.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
734TRUEumpdc.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
735TRUEunattend.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
736TRUEunityplayer.dll*\Appdata\local\Temp\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
737TRUEupdatepolicy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
738TRUEupdatepolicy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
739TRUEupshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
740TRUEurlmon.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
741TRUEurlmon.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
742TRUEuserenv.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
743TRUEuserenv.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
744TRUEutildll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
745TRUEutildll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
746TRUEuxinit.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
747TRUEuxinit.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
748TRUEuxtheme.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
749TRUEuxtheme.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
750TRUEvaultcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
751TRUEvaultcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
752TRUEvdsutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
753TRUEvdsutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
754TRUEvender.dll*\Program Files\ASUS\GPU TweakII*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
755TRUEvender.dll*\Program Files\ASUS\VGA COM\*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
756TRUEversion.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
757TRUEversion.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
758TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
759TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
760TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
761TRUEvirtdisk.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
762TRUEvirtdisk.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
763TRUEvivaldi_elf.dll*\Appdata\local\Vivaldi\Application*T1574.002https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
764TRUEvivaldi_elf.dll*\Appdata\local\Vivaldi\Application\*T1574.002https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
765TRUEvntfxf32.dll*\Program Files\Venta\VentaFax & Voice*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
766TRUEvsodscpl.dll*\Program Files\McAfee\VirusScan Enterprise*T1574.002https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/
767TRUEvssapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
768TRUEvssapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
769TRUEvsstrace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
770TRUEvsstrace.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
771TRUEwbemprox.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
772TRUEwbemprox.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
773TRUEwbemsvc.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
774TRUEwbemsvc.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
775TRUEwcmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
776TRUEwcmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
777TRUEwcnnetsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
778TRUEwdi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
779TRUEwdi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
780TRUEwdscore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
781TRUEwdscore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
782TRUEwebservices.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
783TRUEwebservices.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
784TRUEwecapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
785TRUEwecapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
786TRUEwer.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
787TRUEwer.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
788TRUEwevtapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
789TRUEwevtapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
790TRUEwhhelper.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
791TRUEwhhelper.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
792TRUEwimgapi.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
793TRUEwimgapi.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
794TRUEwimgapi.dll*\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
795TRUEwinbio.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
796TRUEwinbio.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
797TRUEwinbrand.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
798TRUEwinbrand.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
799TRUEwindows.storage.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
800TRUEwindows.storage.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
801TRUEwindows.storage.search.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
802TRUEwindows.storage.search.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
803TRUEwindows.ui.immersive.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
804TRUEwindows.ui.immersive.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
805TRUEwindowscodecs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
806TRUEwindowscodecs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
807TRUEwindowscodecsext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
808TRUEwindowscodecsext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
809TRUEwindowsperformancerecordercontrol.dll*\Program Files\windows kits\10\windows performance toolkit*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
810TRUEwindowsperformancerecordercontrol.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
811TRUEwindowsperformancerecordercontrol.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
812TRUEwindowsperformancerecorderui.dll*\Program Files\Windows Kits\10\Windows Performance Toolkit*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
813TRUEwindowsudk.shellcommon.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
814TRUEwindowsudk.shellcommon.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
815TRUEwinhttp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
816TRUEwinhttp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
817TRUEwininet.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
818TRUEwininet.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
819TRUEwinipsec.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
820TRUEwinipsec.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
821TRUEwinmde.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
822TRUEwinmm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
823TRUEwinmm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
824TRUEwinnsi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
825TRUEwinnsi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
826TRUEwinrnr.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
827TRUEwinrnr.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
828TRUEwinscard.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
829TRUEwinscard.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
830TRUEwinsqlite3.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
831TRUEwinsqlite3.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
832TRUEwinsta.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
833TRUEwinsta.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
834TRUEwinsync.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
835TRUEwinsync.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
836TRUEwinutils.dll*\Program Files\Palo Alto Networks\Traps*T1574.002https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
837TRUEwkscli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
838TRUEwkscli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
839TRUEwlanapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
840TRUEwlanapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
841TRUEwlancfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
842TRUEwlancfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
843TRUEwldp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
844TRUEwldp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
845TRUEwlidprov.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
846TRUEwlidprov.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
847TRUEwmiclnt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
848TRUEwmiclnt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
849TRUEwmidcom.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
850TRUEwmidcom.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
851TRUEwmiutils.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
852TRUEwmiutils.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
853TRUEwmpdui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
854TRUEwmsgapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
855TRUEwmsgapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
856TRUEwofutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
857TRUEwofutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
858TRUEwpdshext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
859TRUEwpdshext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
860TRUEwsc.dll*\Program Files\AVAST Software\Avast*T1574.001https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2
861TRUEwscapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
862TRUEwscapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
863TRUEwsdapi.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
864TRUEwsdapi.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
865TRUEwshbth.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
866TRUEwshbth.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
867TRUEwshelper.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
868TRUEwshelper.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
869TRUEwsmsvc.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
870TRUEwsmsvc.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
871TRUEwtsapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
872TRUEwtsapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
873TRUEwwancfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
874TRUEwwancfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
875TRUEwwapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
876TRUEwwapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
877TRUExmllite.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
878TRUExmllite.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
879TRUExolehlp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
880TRUExolehlp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
881TRUExpsservices.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
882TRUExpsservices.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
883TRUExwizards.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
884TRUExwizards.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
885TRUExwtpw32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
886TRUExwtpw32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables