mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
100 KiB
100 KiB
| 1 | islibrary | library | excludes | ttp | comment |
|---|---|---|---|---|---|
| 2 | TRUE | aclui.dll | *\Windows\System32\* | T1574.002 | https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ |
| 3 | TRUE | aclui.dll | *\Windows\SysWOW64\* | T1574.002 | https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ |
| 4 | TRUE | acrodistdll.dll | *\Program Files\Adobe\Acrobat * | T1574.002 | https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf |
| 5 | TRUE | acrodistdll.dll | *\Acrobat\acrodistdll* | T1574.002 | https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf |
| 6 | TRUE | activeds.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 7 | TRUE | activeds.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 8 | TRUE | adsldpc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 9 | TRUE | adsldpc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 10 | TRUE | aepic.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 11 | TRUE | aepic.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 12 | TRUE | apphelp.dll | *\Windows\System32\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 13 | TRUE | apphelp.dll | *\Windows\SysWOW64\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 14 | TRUE | applicationframe.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 15 | TRUE | applicationframe.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 16 | TRUE | appvpolicy.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 17 | TRUE | appwiz.cpl | *\Windows\System32\* | T1574.002 | https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ |
| 18 | TRUE | appwiz.cpl | *\Windows\SysWOW64\* | T1574.002 | https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/ |
| 19 | TRUE | appxalluserstore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 20 | TRUE | appxalluserstore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 21 | TRUE | appxdeploymentclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 22 | TRUE | appxdeploymentclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 23 | TRUE | archiveint.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 24 | TRUE | archiveint.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 25 | TRUE | ashldres.dll | *\Program Files\McAfee.com\VSO* | T1574.002 | https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf |
| 26 | TRUE | atl.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 27 | TRUE | atl.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 28 | TRUE | atltracetoolui.dll | *\Program Files\Microsoft Visual Studio 11.0\Common7\Tools* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 29 | TRUE | audioses.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 30 | TRUE | audioses.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 31 | TRUE | auditpolcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 32 | TRUE | auditpolcore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 33 | TRUE | authfwcfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 34 | TRUE | authfwcfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 35 | TRUE | authz.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 36 | TRUE | authz.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 37 | TRUE | avrt.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 38 | TRUE | avrt.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 39 | TRUE | basicnetutils.dll | *\Appdata\local\Temp\* | T1574.002 | https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ |
| 40 | TRUE | basicnetutils.dll | *\Program Files\BAIDU\BAIDUPINYIN\* | T1574.002 | https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ |
| 41 | TRUE | batmeter.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 42 | TRUE | batmeter.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 43 | TRUE | bcd.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 44 | TRUE | bcd.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 45 | TRUE | bcp47langs.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 46 | TRUE | bcp47langs.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 47 | TRUE | bcp47mrm.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 48 | TRUE | bcp47mrm.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 49 | TRUE | bcrypt.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 50 | TRUE | bcrypt.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 51 | TRUE | bderepair.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 52 | TRUE | bootmenuux.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 53 | TRUE | bootux.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 54 | TRUE | cabinet.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 55 | TRUE | cabinet.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 56 | TRUE | cabview.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 57 | TRUE | cabview.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 58 | TRUE | certcli.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 59 | TRUE | certcli.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 60 | TRUE | certenroll.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 61 | TRUE | certenroll.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 62 | TRUE | cfgmgr32.dll | *\Windows\System32\* | T1574.002 | |
| 63 | TRUE | cfgmgr32.dll | *\Windows\SysWOW64\* | T1574.002 | |
| 64 | TRUE | chrome_frame_helper.dll | *\Appdata\local\Google\Chrome\Application* | T1574.002 | https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ |
| 65 | TRUE | chrome_frame_helper.dll | *\Program Files\Google\Chrome\Application* | T1574.002 | https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ |
| 66 | TRUE | ciscosparklauncher.dll | *\Appdata\local\CiscoSparkLauncher* | T1574.002 | https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ |
| 67 | TRUE | ciscosparklauncher.dll | *\AppData\Local\Programs\Cisco Spark\* | T1574.002 | https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ |
| 68 | TRUE | classicexplorer32.dll | *\Program Files\Classic Shell* | T1574.002 | https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets |
| 69 | TRUE | classicexplorer32.dll | *\Program Files\Open-Shell* | T1574.002 | https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets |
| 70 | TRUE | cldapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 71 | TRUE | cldapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 72 | TRUE | clipc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 73 | TRUE | clipc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 74 | TRUE | clusapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 75 | TRUE | clusapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 76 | TRUE | cmpbk32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 77 | TRUE | cmpbk32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 78 | TRUE | cmutil.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 79 | TRUE | cmutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 80 | TRUE | coloradapterclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 81 | TRUE | coloradapterclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 82 | TRUE | colorui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 83 | TRUE | colorui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 84 | TRUE | comdlg32.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 85 | TRUE | comdlg32.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 86 | TRUE | commfunc.dll | *\Program Files\Lenovo\Communications Utility* | T1574.002 | https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ |
| 87 | TRUE | configmanager2.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 88 | TRUE | connect.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 89 | TRUE | connect.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 90 | TRUE | coredplus.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 91 | TRUE | coremessaging.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 92 | TRUE | coremessaging.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 93 | TRUE | coreuicomponents.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 94 | TRUE | coreuicomponents.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 95 | TRUE | credui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 96 | TRUE | credui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 97 | TRUE | cryptbase.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 98 | TRUE | cryptbase.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 99 | TRUE | cryptdll.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 100 | TRUE | cryptdll.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 101 | TRUE | cryptsp.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 102 | TRUE | cryptsp.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 103 | TRUE | cryptui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 104 | TRUE | cryptui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 105 | TRUE | cryptxml.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 106 | TRUE | cryptxml.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 107 | TRUE | cscapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 108 | TRUE | cscapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 109 | TRUE | cscobj.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 110 | TRUE | cscobj.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 111 | TRUE | cscui.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 112 | TRUE | cscui.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 113 | TRUE | d2d1.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 114 | TRUE | d2d1.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 115 | TRUE | d3d10.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 116 | TRUE | d3d10.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 117 | TRUE | d3d10_1.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 118 | TRUE | d3d10_1.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 119 | TRUE | d3d10_1core.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 120 | TRUE | d3d10_1core.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 121 | TRUE | d3d10core.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 122 | TRUE | d3d10core.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 123 | TRUE | d3d10warp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 124 | TRUE | d3d10warp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 125 | TRUE | d3d11.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 126 | TRUE | d3d11.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 127 | TRUE | d3d12.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 128 | TRUE | d3d12.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 129 | TRUE | d3d9.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 130 | TRUE | d3d9.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 131 | TRUE | d3dcompiler_47.dll | *\Program Files\windows kits\10\bin\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 132 | TRUE | d3dcompiler_47.dll | *\Program Files\windows kits\10\bin\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 133 | TRUE | d3dcompiler_47.dll | *\Program Files\windows kits\10\redist\d3d\x64* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 134 | TRUE | d3dcompiler_47.dll | *\Program Files\windows kits\10\redist\d3d\x86* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 135 | TRUE | d3dcompiler_47.dll | *\Program Files\wireshark* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 136 | TRUE | d3dcompiler_47.dll | *\Program Files\cisco systems\cisco jabber* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 137 | TRUE | d3dcompiler_47.dll | *\Program Files\microsoft\edge\application\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 138 | TRUE | d3dcompiler_47.dll | *\Program Files\Google\Chrome\Application\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 139 | TRUE | d3dcompiler_47.dll | *\Appdata\local\microsoft\teams\stage* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 140 | TRUE | d3dcompiler_47.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 141 | TRUE | d3dcompiler_47.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 142 | TRUE | d3dcompiler_47.dll | *\Microsoft\Teams\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 143 | TRUE | d3dx9_43.dll | *\Windows\System32\* | T1574.002 | https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ |
| 144 | TRUE | d3dx9_43.dll | *\Windows\SysWOW64\* | T1574.002 | https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ |
| 145 | TRUE | dataexchange.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 146 | TRUE | dataexchange.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 147 | TRUE | davclnt.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 148 | TRUE | davclnt.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 149 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\arm* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 150 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\arm\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 151 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\arm64* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 152 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\arm64\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 153 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\x64* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 154 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\x64\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 155 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\x86* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 156 | TRUE | dbgcore.dll | *\Program Files\windows kits\10\debuggers\x86\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 157 | TRUE | dbgcore.dll | *\Program Files\microsoft office\root\office* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 158 | TRUE | dbgcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 159 | TRUE | dbgcore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 160 | TRUE | dbgeng.dll | *\Program Files\Windows Kits\* | T1574.002 | https://twitter.com/mrexodia/status/1630320327967252483 |
| 161 | TRUE | dbgeng.dll | *\Program Files\Windows Kits\* | T1574.002 | https://twitter.com/mrexodia/status/1630320327967252483 |
| 162 | TRUE | dbgeng.dll | *\Program Files\Windows Kits\* | T1574.002 | https://twitter.com/mrexodia/status/1630320327967252483 |
| 163 | TRUE | dbgeng.dll | *\Program Files\Windows Kits\* | T1574.002 | https://twitter.com/mrexodia/status/1630320327967252483 |
| 164 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\arm* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 165 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\arm\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 166 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\arm64* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 167 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\arm64\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 168 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\x64* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 169 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\x64\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 170 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\x86* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 171 | TRUE | dbghelp.dll | *\Program Files\windows kits\10\debuggers\x86\srcsrv* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 172 | TRUE | dbghelp.dll | *\Program Files\cisco systems\cisco jabber* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 173 | TRUE | dbghelp.dll | *\Program Files\microsoft office\root\office* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 174 | TRUE | dbghelp.dll | *\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 175 | TRUE | dbghelp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 176 | TRUE | dbghelp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 177 | TRUE | dbgmodel.dll | *\Windows\System32\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 178 | TRUE | dbgmodel.dll | *\Windows\SysWOW64\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 179 | TRUE | dbgmodel.dll | *\Program Files\Windows Kits\10\Debuggers\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 180 | TRUE | dcntel.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 181 | TRUE | dcomp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 182 | TRUE | dcomp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 183 | TRUE | defragproxy.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 184 | TRUE | defragproxy.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 185 | TRUE | desktopshellext.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 186 | TRUE | desktopshellext.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 187 | TRUE | deviceassociation.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 188 | TRUE | deviceassociation.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 189 | TRUE | devicecredential.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 190 | TRUE | devicecredential.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 191 | TRUE | devicepairing.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 192 | TRUE | devicepairing.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 193 | TRUE | devobj.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 194 | TRUE | devobj.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 195 | TRUE | devrtl.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 196 | TRUE | devrtl.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 197 | TRUE | dhcpcmonitor.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 198 | TRUE | dhcpcmonitor.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 199 | TRUE | dhcpcsvc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 200 | TRUE | dhcpcsvc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 201 | TRUE | dhcpcsvc6.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 202 | TRUE | dhcpcsvc6.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 203 | TRUE | directmanipulation.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 204 | TRUE | directmanipulation.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 205 | TRUE | dismapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 206 | TRUE | dismapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 207 | TRUE | dismcore.dll | *\Windows\System32\dism* | T1574.001 | https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ |
| 208 | TRUE | dismcore.dll | *\Windows\SysWOW64\dism* | T1574.001 | https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/ |
| 209 | TRUE | dmcfgutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 210 | TRUE | dmcfgutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 211 | TRUE | dmcmnutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 212 | TRUE | dmcmnutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 213 | TRUE | dmcommandlineutils.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 214 | TRUE | dmcommandlineutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 215 | TRUE | dmenrollengine.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 216 | TRUE | dmenrollengine.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 217 | TRUE | dmenterprisediagnostics.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 218 | TRUE | dmiso8601utils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 219 | TRUE | dmiso8601utils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 220 | TRUE | dmoleaututils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 221 | TRUE | dmoleaututils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 222 | TRUE | dmprocessxmlfiltered.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 223 | TRUE | dmprocessxmlfiltered.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 224 | TRUE | dmpushproxy.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 225 | TRUE | dmpushproxy.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 226 | TRUE | dmxmlhelputils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 227 | TRUE | dmxmlhelputils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 228 | TRUE | dnsapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 229 | TRUE | dnsapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 230 | TRUE | dot3api.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 231 | TRUE | dot3api.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 232 | TRUE | dot3cfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 233 | TRUE | dot3cfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 234 | TRUE | dpx.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 235 | TRUE | dpx.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 236 | TRUE | drprov.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 237 | TRUE | drprov.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 238 | TRUE | drvstore.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 239 | TRUE | drvstore.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 240 | TRUE | dsclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 241 | TRUE | dsclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 242 | TRUE | dsparse.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 243 | TRUE | dsparse.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 244 | TRUE | dsprop.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 245 | TRUE | dsprop.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 246 | TRUE | dsreg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 247 | TRUE | dsreg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 248 | TRUE | dsrole.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 249 | TRUE | dsrole.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 250 | TRUE | dui70.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 251 | TRUE | dui70.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 252 | TRUE | duser.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 253 | TRUE | duser.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 254 | TRUE | dusmapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 255 | TRUE | dusmapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 256 | TRUE | dwmapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 257 | TRUE | dwmapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 258 | TRUE | dwmcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 259 | TRUE | dwrite.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 260 | TRUE | dwrite.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 261 | TRUE | dxcore.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 262 | TRUE | dxcore.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 263 | TRUE | dxgi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 264 | TRUE | dxgi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 265 | TRUE | dxva2.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 266 | TRUE | dxva2.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 267 | TRUE | dynamoapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 268 | TRUE | eappcfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 269 | TRUE | eappcfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 270 | TRUE | eappprxy.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 271 | TRUE | eappprxy.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 272 | TRUE | edgeiso.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 273 | TRUE | edgeiso.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 274 | TRUE | edputil.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 275 | TRUE | edputil.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 276 | TRUE | efsadu.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 277 | TRUE | efsadu.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 278 | TRUE | efsutil.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 279 | TRUE | efsutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 280 | TRUE | esent.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 281 | TRUE | esent.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 282 | TRUE | execmodelproxy.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 283 | TRUE | execmodelproxy.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 284 | TRUE | explorerframe.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 285 | TRUE | explorerframe.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 286 | TRUE | facesdk.dll | *\Program Files\luxand\facesdk\bin\win64* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 287 | TRUE | fastprox.dll | *\Windows\System32\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 288 | TRUE | fastprox.dll | *\Windows\SysWOW64\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 289 | TRUE | faultrep.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 290 | TRUE | faultrep.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 291 | TRUE | fddevquery.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 292 | TRUE | fddevquery.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 293 | TRUE | feclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 294 | TRUE | feclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 295 | TRUE | fhcfg.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 296 | TRUE | fhcfg.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 297 | TRUE | fhsvcctl.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 298 | TRUE | firewallapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 299 | TRUE | firewallapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 300 | TRUE | flightsettings.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 301 | TRUE | flightsettings.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 302 | TRUE | fltlib.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 303 | TRUE | fltlib.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 304 | TRUE | formdll.dll | *\Program Files\Common Files\Microsoft Shared\NoteSync Forms* | T1574.002 | https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1 |
| 305 | TRUE | framedynos.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 306 | TRUE | framedynos.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 307 | TRUE | fveapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 308 | TRUE | fveapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 309 | TRUE | fveskybackup.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 310 | TRUE | fvewiz.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 311 | TRUE | fwbase.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 312 | TRUE | fwbase.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 313 | TRUE | fwcfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 314 | TRUE | fwcfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 315 | TRUE | fwpolicyiomgr.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 316 | TRUE | fwpolicyiomgr.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 317 | TRUE | fwpuclnt.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 318 | TRUE | fwpuclnt.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 319 | TRUE | fxsapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 320 | TRUE | fxsapi.dll | *\Windows\System32\driverstore\filerepository\prnms002.inf_* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 321 | TRUE | fxsapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 322 | TRUE | fxsst.dll | *\Windows\System32\* | T1574.001 | https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/ |
| 323 | TRUE | fxstiff.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 324 | TRUE | fxstiff.dll | *\Windows\System32\driverstore\filerepository\prnms002.inf_* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 325 | TRUE | getuname.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 326 | TRUE | getuname.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 327 | TRUE | gflagsui.dll | *\Program Files\Windows Kits\10\Debuggers\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 328 | TRUE | glib-2.0.dll | *\Program Files\VMware\VMware Tools* | T1574.002 | https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ |
| 329 | TRUE | glib-2.0.dll | *\Program Files\VMware\VMware Workstation* | T1574.002 | https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ |
| 330 | TRUE | glib-2.0.dll | *\Program Files\VMware\VMware Player* | T1574.002 | https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/ |
| 331 | TRUE | gpapi.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 332 | TRUE | gpapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 333 | TRUE | hha.dll | *\Windows\System32\* | T1574.002 | https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ |
| 334 | TRUE | hha.dll | *\Windows\SysWOW64\* | T1574.002 | https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ |
| 335 | TRUE | hha.dll | *\Program Files\HTML Help Workshop* | T1574.002 | https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/ |
| 336 | TRUE | hid.dll | *\Windows\System32\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 337 | TRUE | hid.dll | *\Windows\SysWOW64\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 338 | TRUE | hnetmon.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 339 | TRUE | hnetmon.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 340 | TRUE | hpcustpartui.dll | *\Program Files\HP* | T1574.002 | https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html |
| 341 | TRUE | hpqhvsei.dll | *\Program Files\HP* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 342 | TRUE | httpapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 343 | TRUE | httpapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 344 | TRUE | icmp.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 345 | TRUE | icmp.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 346 | TRUE | idstore.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 347 | TRUE | idstore.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 348 | TRUE | ieadvpack.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 349 | TRUE | ieadvpack.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 350 | TRUE | iedkcs32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 351 | TRUE | iedkcs32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 352 | TRUE | iernonce.dll | *\Windows\System32\* | T1574.002 | https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ |
| 353 | TRUE | iernonce.dll | *\Windows\SysWOW64\* | T1574.002 | https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/ |
| 354 | TRUE | iertutil.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 355 | TRUE | iertutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 356 | TRUE | ifmon.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 357 | TRUE | ifmon.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 358 | TRUE | ifsutil.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 359 | TRUE | ifsutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 360 | TRUE | inproclogger.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 361 | TRUE | iphlpapi.dll | *\Windows\System32\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 362 | TRUE | iphlpapi.dll | *\Windows\SysWOW64\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 363 | TRUE | iri.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 364 | TRUE | iri.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 365 | TRUE | iscsidsc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 366 | TRUE | iscsidsc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 367 | TRUE | iscsiexe.dll | *\Windows\System32\* | T1574.001 | https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC |
| 368 | TRUE | iscsiexe.dll | *\Windows\SysWOW64\* | T1574.001 | https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC |
| 369 | TRUE | iscsium.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 370 | TRUE | iscsium.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 371 | TRUE | isv.exe_rsaenh.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 372 | TRUE | isv.exe_rsaenh.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 373 | TRUE | iumbase.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 374 | TRUE | iumsdk.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 375 | TRUE | iviewers.dll | *\Program Files\Windows Kits\10\bin\* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 376 | TRUE | iviewers.dll | *\Program Files\Windows Kits\10\bin\* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 377 | TRUE | iviewers.dll | *\Program Files\Windows Kits\10\bin\* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 378 | TRUE | iviewers.dll | *\Program Files\Windows Kits\10\bin\* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 379 | TRUE | joinutil.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 380 | TRUE | joinutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 381 | TRUE | kdstub.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 382 | TRUE | ksuser.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 383 | TRUE | ksuser.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 384 | TRUE | ktmw32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 385 | TRUE | ktmw32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 386 | TRUE | ldvpocx.ocx | *\Program Files\Symantec_Client_Security\Symantec AntiVirus* | T1574.002 | https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox |
| 387 | TRUE | ldvpocx.ocx | *\Program Files\Symantec AntiVirus* | T1574.002 | https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox |
| 388 | TRUE | libcares-2.dll | *\git\mingw64\* | T1574.002 | https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/ |
| 389 | TRUE | libvlc.dll | *\Program Files\VideoLAN\VLC* | T1574.002 | https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/ |
| 390 | TRUE | licensemanagerapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 391 | TRUE | licensemanagerapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 392 | TRUE | licensingdiagspp.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 393 | TRUE | licensingdiagspp.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 394 | TRUE | linkinfo.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 395 | TRUE | linkinfo.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 396 | TRUE | lmiguardiandll.dll | *\Program Files\LogMeIn* | T1574.002 | https://twitter.com/StopMalvertisin/status/1610961056163311619 |
| 397 | TRUE | lmiguardiandll.dll | *\Program Files\LogMeIn\x86* | T1574.002 | https://twitter.com/StopMalvertisin/status/1610961056163311619 |
| 398 | TRUE | lmiguardiandll.dll | *\Program Files\LogMeIn\x64* | T1574.002 | https://twitter.com/StopMalvertisin/status/1610961056163311619 |
| 399 | TRUE | loadperf.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 400 | TRUE | loadperf.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 401 | TRUE | lockdown.dll | *\Program Files\McAfee\VirusScan Enterprise* | T1574.002 | https://twitter.com/thepacketrat/status/1520878930449817600 |
| 402 | TRUE | lockhostingframework.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 403 | TRUE | log.dll | *\Program Files\Bitdefender Antivirus Free* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 404 | TRUE | logoncli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 405 | TRUE | logoncli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 406 | TRUE | logoncontroller.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 407 | TRUE | logoncontroller.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 408 | TRUE | lpksetupproxyserv.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 409 | TRUE | lpksetupproxyserv.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 410 | TRUE | lrwizdll.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 411 | TRUE | magnification.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 412 | TRUE | magnification.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 413 | TRUE | maintenanceui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 414 | TRUE | mapistub.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 415 | TRUE | mapistub.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 416 | TRUE | mbaexmlparser.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 417 | TRUE | mdmdiagnostics.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 418 | TRUE | mfc42u.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 419 | TRUE | mfc42u.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 420 | TRUE | mfcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 421 | TRUE | mfcore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 422 | TRUE | mfplat.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 423 | TRUE | mfplat.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 424 | TRUE | mi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 425 | TRUE | mi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 426 | TRUE | midimap.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 427 | TRUE | midimap.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 428 | TRUE | mintdh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 429 | TRUE | miutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 430 | TRUE | miutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 431 | TRUE | mlang.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 432 | TRUE | mlang.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 433 | TRUE | mmdevapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 434 | TRUE | mmdevapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 435 | TRUE | mobilenetworking.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 436 | TRUE | mobilenetworking.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 437 | TRUE | mozglue.dll | *\Program Files\SeaMonkey* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 438 | TRUE | mozglue.dll | *\Program Files\Mozilla Firefox* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 439 | TRUE | mozglue.dll | *\Program Files\Mozilla Thunderbird* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 440 | TRUE | mozglue.dll | *\AppData\Local\Mozilla Firefox\* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 441 | TRUE | mpclient.dll | *\Program Files\Windows Defender* | T1574.002 | https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ |
| 442 | TRUE | mpclient.dll | *\ProgramData\Microsoft\Windows Defender\Platform\* | T1574.002 | https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/ |
| 443 | TRUE | mpr.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 444 | TRUE | mpr.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 445 | TRUE | mprapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 446 | TRUE | mprapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 447 | TRUE | mpsvc.dll | *\Program Files\Windows Defender\* | T1574.002 | https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ |
| 448 | TRUE | mpsvc.dll | *\ProgramData\Microsoft\Windows Defender\Platform\* | T1574.002 | https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/ |
| 449 | TRUE | mrmcorer.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 450 | TRUE | mrmcorer.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 451 | TRUE | msacm32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 452 | TRUE | msacm32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 453 | TRUE | mscms.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 454 | TRUE | mscms.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 455 | TRUE | mscoree.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 456 | TRUE | mscoree.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 457 | TRUE | mscorsvc.dll | *\Windows\Microsoft.NET\Framework\v* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 458 | TRUE | mscorsvc.dll | *\Windows\Microsoft.NET\Framework64\v* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 459 | TRUE | msctf.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 460 | TRUE | msctf.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 461 | TRUE | msctfmonitor.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 462 | TRUE | msctfmonitor.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 463 | TRUE | msdrm.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 464 | TRUE | msdrm.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 465 | TRUE | msdtctm.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 466 | TRUE | msftedit.dll | *\Windows\System32\* | T1574.002 | https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ |
| 467 | TRUE | msftedit.dll | *\Windows\SysWOW64\* | T1574.002 | https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ |
| 468 | TRUE | msi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 469 | TRUE | msi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 470 | TRUE | msiso.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 471 | TRUE | msiso.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 472 | TRUE | msutb.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 473 | TRUE | msutb.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 474 | TRUE | msvcp110_win.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 475 | TRUE | msvcp110_win.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 476 | TRUE | msvcr100.dll | *\Windows\System32\* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 477 | TRUE | msvcr100.dll | *\Windows\SysWOW64\* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 478 | TRUE | mswb7.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 479 | TRUE | mswb7.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 480 | TRUE | mswsock.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 481 | TRUE | mswsock.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 482 | TRUE | msxml3.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 483 | TRUE | msxml3.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 484 | TRUE | mtxclu.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 485 | TRUE | mtxclu.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 486 | TRUE | napinsp.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 487 | TRUE | napinsp.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 488 | TRUE | ncrypt.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 489 | TRUE | ncrypt.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 490 | TRUE | ndfapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 491 | TRUE | ndfapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 492 | TRUE | netapi32.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 493 | TRUE | netapi32.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 494 | TRUE | netid.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 495 | TRUE | netid.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 496 | TRUE | netiohlp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 497 | TRUE | netiohlp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 498 | TRUE | netjoin.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 499 | TRUE | netjoin.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 500 | TRUE | netplwiz.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 501 | TRUE | netplwiz.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 502 | TRUE | netprofm.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 503 | TRUE | netprofm.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 504 | TRUE | netprovfw.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 505 | TRUE | netprovfw.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 506 | TRUE | netsetupapi.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 507 | TRUE | netsetupapi.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 508 | TRUE | netshell.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 509 | TRUE | netshell.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 510 | TRUE | nettrace.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 511 | TRUE | netutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 512 | TRUE | netutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 513 | TRUE | networkexplorer.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 514 | TRUE | networkexplorer.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 515 | TRUE | newdev.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 516 | TRUE | newdev.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 517 | TRUE | ninput.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 518 | TRUE | ninput.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 519 | TRUE | nlaapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 520 | TRUE | nlaapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 521 | TRUE | nlansp_c.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 522 | TRUE | nlansp_c.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 523 | TRUE | npmproxy.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 524 | TRUE | npmproxy.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 525 | TRUE | nshhttp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 526 | TRUE | nshhttp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 527 | TRUE | nshipsec.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 528 | TRUE | nshipsec.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 529 | TRUE | nshwfp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 530 | TRUE | nshwfp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 531 | TRUE | ntdsapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 532 | TRUE | ntdsapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 533 | TRUE | ntlanman.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 534 | TRUE | ntlanman.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 535 | TRUE | ntlmshared.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 536 | TRUE | ntlmshared.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 537 | TRUE | ntmarta.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 538 | TRUE | ntmarta.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 539 | TRUE | ntshrui.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 540 | TRUE | ntshrui.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 541 | TRUE | nvsmartmax.dll | *\Program Files\NVIDIA Corporation\Display* | T1574.002 | https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos |
| 542 | TRUE | oleacc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 543 | TRUE | oleacc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 544 | TRUE | omadmapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 545 | TRUE | omadmapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 546 | TRUE | onex.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 547 | TRUE | onex.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 548 | TRUE | opcservices.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 549 | TRUE | opcservices.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 550 | TRUE | opera_elf.dll | *\Appdata\local\programs\opera\* | T1574.002 | https://twitter.com/ShitSecure/status/1566127363389329412 |
| 551 | TRUE | osbaseln.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 552 | TRUE | osbaseln.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 553 | TRUE | osksupport.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 554 | TRUE | osuninst.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 555 | TRUE | osuninst.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 556 | TRUE | outllib.dll | *\Program Files\Microsoft Office\OFFICE* | T1574.002 | https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 |
| 557 | TRUE | outllib.dll | *\Program Files\Microsoft Office\Root\OFFICE* | T1574.002 | https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6 |
| 558 | TRUE | p2p.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 559 | TRUE | p2p.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 560 | TRUE | p2pnetsh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 561 | TRUE | p2pnetsh.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 562 | TRUE | p9np.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 563 | TRUE | p9np.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 564 | TRUE | pcaui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 565 | TRUE | pcaui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 566 | TRUE | pdh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 567 | TRUE | pdh.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 568 | TRUE | peerdistsh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 569 | TRUE | peerdistsh.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 570 | TRUE | pkeyhelper.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 571 | TRUE | pla.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 572 | TRUE | pla.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 573 | TRUE | playsndsrv.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 574 | TRUE | playsndsrv.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 575 | TRUE | pnrpnsp.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 576 | TRUE | pnrpnsp.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 577 | TRUE | policymanager.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 578 | TRUE | policymanager.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 579 | TRUE | polstore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 580 | TRUE | polstore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 581 | TRUE | powrprof.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 582 | TRUE | powrprof.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 583 | TRUE | printui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 584 | TRUE | printui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 585 | TRUE | prntvpt.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 586 | TRUE | prntvpt.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 587 | TRUE | profapi.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 588 | TRUE | profapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 589 | TRUE | propsys.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 590 | TRUE | propsys.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 591 | TRUE | proximitycommon.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 592 | TRUE | proximitycommon.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 593 | TRUE | proximityservicepal.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 594 | TRUE | prvdmofcomp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 595 | TRUE | prvdmofcomp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 596 | TRUE | puiapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 597 | TRUE | puiapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 598 | TRUE | python39.dll | *\Program Files\Python39* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 599 | TRUE | python39.dll | *\Appdata\local\Temp\* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 600 | TRUE | python39.dll | *\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 601 | TRUE | python39.dll | *\Users\anaconda3* | T1574.002 | https://twitter.com/SBousseaden/status/1530595156055011330 |
| 602 | TRUE | qrt.dll | *\Program Files\F-Secure\Anti-Virus* | T1574.002 | https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/ |
| 603 | TRUE | radcui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 604 | TRUE | radcui.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 605 | TRUE | rasapi32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 606 | TRUE | rasapi32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 607 | TRUE | rasdlg.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 608 | TRUE | rasdlg.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 609 | TRUE | rasgcw.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 610 | TRUE | rasgcw.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 611 | TRUE | rasman.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 612 | TRUE | rasman.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 613 | TRUE | rasmontr.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 614 | TRUE | rasmontr.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 615 | TRUE | rastls.dll | *\Program Files\Symantec\Network Connected Devices Auto Setup* | T1574.002 | https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf |
| 616 | TRUE | rcdll.dll | *\Program Files\Windows Kits\10\bin\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 617 | TRUE | reagent.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 618 | TRUE | reagent.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 619 | TRUE | regapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 620 | TRUE | regapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 621 | TRUE | reseteng.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 622 | TRUE | resetengine.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 623 | TRUE | resutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 624 | TRUE | resutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 625 | TRUE | rjvplatform.dll | *\Windows\System32\SystemResetPlatform* | T1574.002 | https://twitter.com/0gtweet/status/1666716511988330499 |
| 626 | TRUE | rjvplatform.dll | *\Windows\SysWOW64\SystemResetPlatform* | T1574.002 | https://twitter.com/0gtweet/status/1666716511988330499 |
| 627 | TRUE | rmclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 628 | TRUE | rmclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 629 | TRUE | rpcnsh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 630 | TRUE | rpcnsh.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 631 | TRUE | rsaenh.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 632 | TRUE | rsaenh.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 633 | TRUE | rtutils.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 634 | TRUE | rtutils.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 635 | TRUE | rtworkq.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 636 | TRUE | rtworkq.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 637 | TRUE | rzlog4cpp_logger.dll | *\Appdata\local\razer\InGameEngine\cache\RzFpsApplet* | T1574.002 | https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia |
| 638 | TRUE | safestore32.dll | *\Program Files\Sophos\Sophos Anti-Virus* | T1574.002 | https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf |
| 639 | TRUE | samcli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 640 | TRUE | samcli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 641 | TRUE | samlib.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 642 | TRUE | samlib.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 643 | TRUE | sapi_onecore.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 644 | TRUE | sapi_onecore.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 645 | TRUE | sas.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 646 | TRUE | sas.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 647 | TRUE | scansetting.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 648 | TRUE | scansetting.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 649 | TRUE | scecli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 650 | TRUE | scecli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 651 | TRUE | schedcli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 652 | TRUE | schedcli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 653 | TRUE | secur32.dll | *\Windows\System32\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 654 | TRUE | secur32.dll | *\Windows\SysWOW64\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 655 | TRUE | security.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 656 | TRUE | security.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 657 | TRUE | sensapi.dll | *\Windows\System32\* | T1574.002 | https://twitter.com/AndrewOliveau/status/1682185200862625792 |
| 658 | TRUE | sensapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://twitter.com/AndrewOliveau/status/1682185200862625792 |
| 659 | TRUE | shell32.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 660 | TRUE | shell32.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 661 | TRUE | shfolder.dll | *\Windows\System32\* | T1574.002 | https://twitter.com/dissectmalware/status/978017957480628226 |
| 662 | TRUE | shfolder.dll | *\Windows\SysWOW64\* | T1574.002 | https://twitter.com/dissectmalware/status/978017957480628226 |
| 663 | TRUE | siteadv.dll | *\Program Files\SiteAdvisor\* | T1574.002 | https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf |
| 664 | TRUE | slc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 665 | TRUE | slc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 666 | TRUE | smadhook32c.dll | *\Program Files\Smadav* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 667 | TRUE | snmpapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 668 | TRUE | snmpapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 669 | TRUE | spectrumsyncclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 670 | TRUE | spp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 671 | TRUE | spp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 672 | TRUE | sppc.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 673 | TRUE | sppc.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 674 | TRUE | sppcext.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 675 | TRUE | sppcext.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 676 | TRUE | srclient.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 677 | TRUE | srclient.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 678 | TRUE | srcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 679 | TRUE | srmtrace.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 680 | TRUE | srmtrace.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 681 | TRUE | srpapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 682 | TRUE | srpapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 683 | TRUE | srvcli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 684 | TRUE | srvcli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 685 | TRUE | ssp.exe_rsaenh.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 686 | TRUE | ssp.exe_rsaenh.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 687 | TRUE | ssp_isv.exe_rsaenh.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 688 | TRUE | ssp_isv.exe_rsaenh.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 689 | TRUE | sspicli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 690 | TRUE | sspicli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 691 | TRUE | ssshim.dll | *\Windows\System32\* | T1574.002 | https://twitter.com/0gtweet/status/1363107343018385410 |
| 692 | TRUE | ssshim.dll | *\Windows\SysWOW64\* | T1574.002 | https://twitter.com/0gtweet/status/1363107343018385410 |
| 693 | TRUE | staterepository.core.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 694 | TRUE | staterepository.core.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 695 | TRUE | structuredquery.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 696 | TRUE | structuredquery.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 697 | TRUE | sxshared.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 698 | TRUE | sxshared.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 699 | TRUE | symsrv.dll | *\Program Files\Windows Kits\10\Debuggers\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 700 | TRUE | systemsettingsthresholdadminflowui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 701 | TRUE | tapi32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 702 | TRUE | tapi32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 703 | TRUE | tbs.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 704 | TRUE | tbs.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 705 | TRUE | tdh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 706 | TRUE | tdh.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 707 | TRUE | textshaping.dll | *\Windows\System32\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 708 | TRUE | textshaping.dll | *\Windows\SysWOW64\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 709 | TRUE | timesync.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 710 | TRUE | tmdbglog.dll | *\Program Files\Trend Micro\Titanium* | T1574.002 | https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/ |
| 711 | TRUE | tosbtkbd.dll | *\Program Files\Toshiba\Bluetooth Toshiba Stack* | T1574.002 | https://www.secureworks.com/research/shadowpad-malware-analysis |
| 712 | TRUE | tpmcoreprovisioning.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 713 | TRUE | tpmcoreprovisioning.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 714 | TRUE | tquery.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 715 | TRUE | tquery.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 716 | TRUE | tsworkspace.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 717 | TRUE | tsworkspace.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 718 | TRUE | ttdrecord.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 719 | TRUE | ttdrecord.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 720 | TRUE | twext.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 721 | TRUE | twext.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 722 | TRUE | twinapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 723 | TRUE | twinapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/save-the-environment-variables |
| 724 | TRUE | twinui.appcore.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 725 | TRUE | twinui.appcore.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 726 | TRUE | uianimation.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 727 | TRUE | uianimation.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 728 | TRUE | uiautomationcore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 729 | TRUE | uiautomationcore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 730 | TRUE | uireng.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 731 | TRUE | uireng.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 732 | TRUE | uiribbon.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 733 | TRUE | uiribbon.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 734 | TRUE | umpdc.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 735 | TRUE | umpdc.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 736 | TRUE | unattend.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 737 | TRUE | unityplayer.dll | *\Appdata\local\Temp\* | T1574.002 | https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/ |
| 738 | TRUE | updatepolicy.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 739 | TRUE | updatepolicy.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 740 | TRUE | upshared.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 741 | TRUE | urlmon.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 742 | TRUE | urlmon.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 743 | TRUE | userenv.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 744 | TRUE | userenv.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 745 | TRUE | utildll.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 746 | TRUE | utildll.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 747 | TRUE | uxinit.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 748 | TRUE | uxinit.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 749 | TRUE | uxtheme.dll | *\Windows\System32\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 750 | TRUE | uxtheme.dll | *\Windows\SysWOW64\* | T1574.001 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 751 | TRUE | vaultcli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 752 | TRUE | vaultcli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 753 | TRUE | vdsutil.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 754 | TRUE | vdsutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 755 | TRUE | vender.dll | *\Program Files\ASUS\GPU TweakII* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 756 | TRUE | vender.dll | *\Program Files\ASUS\VGA COM\* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 757 | TRUE | version.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 758 | TRUE | version.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 759 | TRUE | vftrace.dll | *\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32* | T1574.002 | https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true |
| 760 | TRUE | vftrace.dll | *\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64* | T1574.002 | https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true |
| 761 | TRUE | vftrace.dll | *\Program Files\CyberArk\Endpoint Privilege Manager\Agent* | T1574.002 | https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true |
| 762 | TRUE | virtdisk.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 763 | TRUE | virtdisk.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 764 | TRUE | vivaldi_elf.dll | *\Appdata\local\Vivaldi\Application* | T1574.002 | https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ |
| 765 | TRUE | vivaldi_elf.dll | *\Appdata\local\Vivaldi\Application\* | T1574.002 | https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/ |
| 766 | TRUE | vntfxf32.dll | *\Program Files\Venta\VentaFax & Voice* | T1574.002 | https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/ |
| 767 | TRUE | vsodscpl.dll | *\Program Files\McAfee\VirusScan Enterprise* | T1574.002 | https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/ |
| 768 | TRUE | vssapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 769 | TRUE | vssapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 770 | TRUE | vsstrace.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 771 | TRUE | vsstrace.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 772 | TRUE | wbemprox.dll | *\Windows\System32\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 773 | TRUE | wbemprox.dll | *\Windows\SysWOW64\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 774 | TRUE | wbemsvc.dll | *\Windows\System32\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 775 | TRUE | wbemsvc.dll | *\Windows\SysWOW64\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 776 | TRUE | wcmapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 777 | TRUE | wcmapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 778 | TRUE | wcnnetsh.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 779 | TRUE | wdi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 780 | TRUE | wdi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 781 | TRUE | wdscore.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 782 | TRUE | wdscore.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 783 | TRUE | webservices.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 784 | TRUE | webservices.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 785 | TRUE | wecapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 786 | TRUE | wecapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 787 | TRUE | wer.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 788 | TRUE | wer.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 789 | TRUE | wevtapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 790 | TRUE | wevtapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 791 | TRUE | whhelper.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 792 | TRUE | whhelper.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 793 | TRUE | wimgapi.dll | *\Windows\System32\* | T1574.002 | https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ |
| 794 | TRUE | wimgapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ |
| 795 | TRUE | wimgapi.dll | *\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM* | T1574.002 | https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/ |
| 796 | TRUE | winbio.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 797 | TRUE | winbio.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 798 | TRUE | winbrand.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 799 | TRUE | winbrand.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 800 | TRUE | windows.storage.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 801 | TRUE | windows.storage.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 802 | TRUE | windows.storage.search.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 803 | TRUE | windows.storage.search.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 804 | TRUE | windows.ui.immersive.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 805 | TRUE | windows.ui.immersive.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 806 | TRUE | windowscodecs.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 807 | TRUE | windowscodecs.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 808 | TRUE | windowscodecsext.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 809 | TRUE | windowscodecsext.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 810 | TRUE | windowsperformancerecordercontrol.dll | *\Program Files\windows kits\10\windows performance toolkit* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 811 | TRUE | windowsperformancerecordercontrol.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 812 | TRUE | windowsperformancerecordercontrol.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 813 | TRUE | windowsperformancerecorderui.dll | *\Program Files\Windows Kits\10\Windows Performance Toolkit* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 814 | TRUE | windowsudk.shellcommon.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 815 | TRUE | windowsudk.shellcommon.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 816 | TRUE | winhttp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 817 | TRUE | winhttp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 818 | TRUE | wininet.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 819 | TRUE | wininet.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 820 | TRUE | winipsec.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 821 | TRUE | winipsec.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 822 | TRUE | winmde.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 823 | TRUE | winmm.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 824 | TRUE | winmm.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 825 | TRUE | winnsi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 826 | TRUE | winnsi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 827 | TRUE | winrnr.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 828 | TRUE | winrnr.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 829 | TRUE | winscard.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 830 | TRUE | winscard.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 831 | TRUE | winsqlite3.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 832 | TRUE | winsqlite3.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 833 | TRUE | winsta.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 834 | TRUE | winsta.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 835 | TRUE | winsync.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 836 | TRUE | winsync.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 837 | TRUE | winutils.dll | *\Program Files\Palo Alto Networks\Traps* | T1574.002 | https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/ |
| 838 | TRUE | wkscli.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 839 | TRUE | wkscli.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 840 | TRUE | wlanapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 841 | TRUE | wlanapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 842 | TRUE | wlancfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 843 | TRUE | wlancfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 844 | TRUE | wldp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 845 | TRUE | wldp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 846 | TRUE | wlidprov.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 847 | TRUE | wlidprov.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 848 | TRUE | wmiclnt.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 849 | TRUE | wmiclnt.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 850 | TRUE | wmidcom.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 851 | TRUE | wmidcom.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 852 | TRUE | wmiutils.dll | *\Windows\System32\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 853 | TRUE | wmiutils.dll | *\Windows\SysWOW64\wbem* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 854 | TRUE | wmpdui.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 855 | TRUE | wmsgapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 856 | TRUE | wmsgapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 857 | TRUE | wofutil.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 858 | TRUE | wofutil.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 859 | TRUE | wpdshext.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 860 | TRUE | wpdshext.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 861 | TRUE | wsc.dll | *\Program Files\AVAST Software\Avast* | T1574.001 | https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2 |
| 862 | TRUE | wscapi.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 863 | TRUE | wscapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 864 | TRUE | wsdapi.dll | *\Windows\System32\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 865 | TRUE | wsdapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/ |
| 866 | TRUE | wshbth.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 867 | TRUE | wshbth.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 868 | TRUE | wshelper.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 869 | TRUE | wshelper.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 870 | TRUE | wsmsvc.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 871 | TRUE | wsmsvc.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 872 | TRUE | wtsapi32.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 873 | TRUE | wtsapi32.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 874 | TRUE | wwancfg.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 875 | TRUE | wwancfg.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 876 | TRUE | wwapi.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 877 | TRUE | wwapi.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 878 | TRUE | xmllite.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 879 | TRUE | xmllite.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 880 | TRUE | xolehlp.dll | *\Windows\System32\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 881 | TRUE | xolehlp.dll | *\Windows\SysWOW64\* | T1574.002 | https://wietze.github.io/blog/hijacking-dlls-in-windows |
| 882 | TRUE | xpsservices.dll | *\Windows\System32\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 883 | TRUE | xpsservices.dll | *\Windows\SysWOW64\* | T1574.002 | https://securityintelligence.com/posts/windows-features-dll-sideloading/ |
| 884 | TRUE | xwizards.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 885 | TRUE | xwizards.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 886 | TRUE | xwtpw32.dll | *\Windows\System32\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |
| 887 | TRUE | xwtpw32.dll | *\Windows\SysWOW64\* | T1574.007 | https://wietze.github.io/blog/save-the-environment-variables |